Red Hat issued Important kernel security updates for CVE-2025-37914, a Linux traffic-control flaw in the net_sched Enhanced Transmission Selection (ETS) queuing discipline. When ETS uses a netem child qdisc, a reentrant enqueue callback can add the same classifier to ETS's active list twice, potentially causing memory corruption. The upstream correction prevents duplicate insertion by confirming both that the queue length is zero and that the class is not already active.
The fix was delivered through RHEL 8, 9, and 10 advisories, including RHEL 10 advisory RHSA-2025:14510, which also addresses CVE-2025-38200 in the i40e driver and CVE-2025-38417 in the ice driver across supported architectures. Red Hat also released updated Real Time Linux Kernel packages for RHEL 9.2 SAP Solutions and Extended Life Cycle systems under RHSA-2025:17735; affected organizations should install kernel-rt-5.14.0-284.142.1.rt14.427.el9_2 where applicable and reboot after updating.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2025:17735 for RHEL 9.2 Update Services for SAP Solutions and RHEL 9.2 Extended Life Cycle on x86_64. The kernel-rt update, version 5.14.0-284.142.1.rt14.427.el9_2, fixes CVE-2025-37914 and requires a reboot.
Red Hat published RHSA-2025:14510, an Important kernel security update for RHEL 10, remediating CVE-2025-37914 along with CVE-2025-38200 and CVE-2025-38417. Updated systems must be rebooted for the fixes to take effect.
The upstream Linux CVE announcement for CVE-2025-37914 was published. The flaw affects the net_sched ETS queuing discipline, where reentrant enqueue processing with a netem child qdisc can add a classifier to the active list twice and cause memory corruption.
Gerrard Tai reported that netem packet duplication can re-enter a classful parent qdisc before netem's queue length is updated, allowing the same child qdisc to be activated twice. An HFSC proof of concept deletes one class and triggers a use-after-free when HFSC subsequently dequeues from it; no patch was proposed.
Red Hat stated that reentrant ETS enqueue processing with a netem child qdisc can insert the same class twice into the active list, corrupting list structures; it said this specific condition does not involve a use-after-free. Red Hat assessed denial of service as the most practical impact, noted that exploitation requires local low-privileged access and a crafted qdisc hierarchy, and recommended preventing sch_ets from loading where ETS is unnecessary.
Red Hat identified advisories addressing CVE-2025-37914 for RHEL 8, RHEL 9, RHEL 9.4 Extended Update Support, and multiple RHEL 8.x and 9.x SAP, telecommunications, mission-critical, and extended-support variants, including RHSA-2025:13960, RHSA-2025:13961, RHSA-2025:14420, RHSA-2025:15668, RHSA-2025:17570, RHSA-2025:17734, RHSA-2025:18043, RHSA-2025:18054, RHSA-2025:18098, and RHSA-2025:22752.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
11 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.