Red Hat released Important kernel security updates for RHEL 9, including the real-time kernel for RHEL 9.2 SAP Solutions and Extended Life Cycle environments, addressing CVE-2025-38332. The flaw affects BIOS-version handling in the Linux SCSI lpfc Fibre Channel driver: FORTIFY-enabled strlcat() can incorrectly flag a destination-buffer overflow and cause a kernel panic despite receiving the correct buffer size.
The upstream remediation replaces the affected zero-initialization and strlcat() logic with memcpy() while retaining NUL termination required by lpfc_printf_log(). RHSA-2025:14005 provides kernel-rt-5.14.0-284.131.1.rt14.416.el9_2 for affected x86_64 RHEL 9.2 SAP and ELC systems; RHSA-2025:15661 delivers fixes across supported RHEL 9 architectures and also addresses three additional kernel flaws. Organizations should install the applicable updated kernel packages and reboot systems to activate the fixes.

See real exploitation activity before you spend the cycle.
9 events from the most recent confirmed update back to the earliest known activity.
Red Hat released Important-rated advisory RHSA-2025:15661 for RHEL 9 kernel packages across supported architectures and applicable support variants. The update remediates CVE-2025-38332 in the lpfc driver along with three other kernel flaws, and requires a reboot after installation.
Red Hat issued Important-rated RHSA-2025:15646 for the kernel-rt package on RHEL for Real Time 7 x86_64 under Extended Lifecycle Support. The update provides kernel-rt-3.10.0-1160.139.1.rt56.1291.el7, fixes CVE-2025-38332 and CVE-2025-38352, and requires affected systems to reboot.
Red Hat issued Important-rated RHSA-2025:15648 for RHEL 7 Extended Life Cycle Support. Kernel version 3.10.0-1160.139.1.el7 fixes CVE-2025-38332 and the POSIX CPU timer race CVE-2025-38352 for x86_64, s390x, ppc64, and ppc64le systems; a reboot is required.
Red Hat issued Important-rated RHSA-2025:15649 for RHEL 8.8 Update Services for SAP Solutions and Extended Life Cycle Long Life systems. The kernel update, version 4.18.0-477.110.1.el8_8 for x86_64 and ppc64le, fixes CVE-2025-38332 alongside three other vulnerabilities and requires a reboot.
Red Hat issued Important-rated RHSA-2025:14003 for RHEL 9.2 kernel packages across AUS, SAP Update Services, four-year update services, and Extended Life Cycle offerings. The update fixes CVE-2025-38332 and four other kernel vulnerabilities, supplies kernel release 5.14.0-284.131.1.el9_2 for x86_64, aarch64, ppc64le, and s390x, and requires a reboot.
Red Hat published an Important-rated security update for RHEL 9.2 Update Services for SAP Solutions and Extended Life Cycle x86_64 systems. RHSA-2025:14005 fixes CVE-2025-38332 and four other kernel vulnerabilities; affected systems must reboot after updating.
An upstream Linux CVE announcement identified CVE-2025-38332 in the SCSI lpfc driver's BIOS-version handling. The remediation replaces memset() and strlcat() usage with memcpy() while preserving NUL termination to prevent a FORTIFY-triggered kernel panic.
An upstream Linux CVE announcement disclosed CVE-2025-38159, an out-of-bounds read in the rtw88 Wi-Fi driver's `para` buffer handling. The fix expands the buffer from two to six bytes so the five-byte read beginning at `para[1]` is safe.
CVE-2025-38352 was documented as a Linux kernel race between handle_posix_cpu_timers() and posix_cpu_timer_del() during task exit and reaping. The upstream fix adds an exit_state check in run_posix_cpu_timers(); the referenced material also states that CISA added the flaw to its Known Exploited Vulnerabilities catalog after confirmed in-the-wild exploitation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
9 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.