Red Hat issued kernel security updates for RHEL 7 Extended Lifecycle Support, RHEL 8, RHEL 9, and RHEL for Real Time 7, remediating vulnerabilities in USB, networking, storage, and scheduler components. The updates address CVE-2022-50229, a use-after-free in the ALSA BCD2000 driver's probe-error path; CVE-2023-53125, which could expose kernel memory through an oversized packet length in the SMSC75xx USB Ethernet driver; and CVE-2025-38392, an invalid locking-context flaw in the idpf network driver when MAC-filter capability is enabled.
The RHEL 7 advisories also cover issues in USB audio, RAID10, Intel i40e networking, and the QFQ scheduler, while the RHEL 9 update includes fixes for the DWC3 USB gadget driver, mount type changes, and the s390 SCLP subsystem. RHEL 8 customers should install kernel version 4.18.0-553.75.1.el8_10; RHEL for Real Time 7 customers should install 3.10.0-1160.140.1.rt56.1292.el7. Administrators should deploy the applicable updated kernel packages across supported architectures and reboot systems to activate the fixes.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-rated RHSA-2025:17161 for RHEL 7 Extended Lifecycle Support on x86_64, s390x, ppc64, and ppc64le. The update fixes CVE-2022-50229 and CVE-2023-53125 among six kernel vulnerabilities; administrators must reboot after applying the supplied kernel build.
Red Hat issued Moderate-rated RHSA-2025:17109 for RHEL for Real Time 7 Extended Life Cycle Support on x86_64. The kernel-rt update fixes CVE-2022-50229 and CVE-2023-53125, among four other kernel vulnerabilities, and requires a reboot.
Red Hat issued Moderate-rated RHSA-2025:16398 for RHEL 9 kernel packages. It remediates CVE-2023-53125 by limiting smsc75xx packet length to skb->len, as well as CVE-2025-37810, CVE-2025-38498, and CVE-2025-39694.
Red Hat issued Important-rated RHSA-2025:15785 for RHEL 8, supplying kernel version 4.18.0-553.75.1.el8_10. The update fixes CVE-2023-53125 and CVE-2025-38392, along with CVE-2025-38350 and CVE-2025-38449; affected systems require a reboot after installation.
An upstream Linux kernel CVE announcement for CVE-2023-53125 was referenced. The flaw in the smsc75xx USB-network driver could allow a packet-length value exceeding skb->len to expose kernel memory through a cloned socket buffer.
Red Hat issued Important-rated RHSA-2025:2473 for RHEL 8, providing kernel version 4.18.0-553.44.1.el8_10. The update fixes four kernel flaws affecting HID, ALSA USB-audio, megaraid_sas, and PPS components; affected systems require a reboot.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.