Red Hat released kernel updates addressing CVE-2025-38211, a use-after-free vulnerability in the Linux kernel's RDMA iWARP Connection Manager (RDMA/iwcm). The flaw can occur when an event-handler work item drops the final reference to a cm_id while the workqueue can still access the associated work object; it was reproducible through the blktests nvme/061 test using RDMA transport and the siw driver.
The fix moves final cm_id reference handling into the connection-manager destruction context, preventing work objects from being freed prematurely. Red Hat included the fix in the Moderate-severity RHEL 8 advisory RHSA-2025:15008, providing kernel 4.18.0-553.72.1.el8_10 for x86_64, aarch64, ppc64le, and s390x systems, including selected Extended Life Cycle deployments; administrators should install the updated packages and reboot. Red Hat also issued related kernel security updates across RHEL product streams, including RHEL 10 packages that remediate multiple kernel flaws.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity RHSA-2025:17192 for RHEL 9.0 Update Services for SAP Solutions on x86_64, updating kernel-rt to version 5.14.0-70.148.1.rt21.220.el9_0. The update fixes CVE-2025-38211 along with CVE-2022-49969, CVE-2022-50211, CVE-2025-38461, and CVE-2025-38449; Red Hat requires a reboot after installation.
Red Hat issued Moderate-severity RHSA-2025:16669 for RHEL 9.4, providing kernel version 5.14.0-427.91.1.el9_4. The update remediates CVE-2025-38211 and four other kernel vulnerabilities across supported RHEL 9.4 channels and architectures; affected systems require a reboot after installation.
Red Hat issued Important-rated RHSA-2025:15669 for RHEL 9.2 Update and Lifecycle Services, providing kernel version 5.14.0-284.137.1.el9_2. The update remediates CVE-2025-38211 along with CVE-2025-22097, CVE-2025-22058, and CVE-2025-38352 across supported architectures and requires a reboot.
Red Hat issued RHSA-2025:15011, an Important advisory providing updated RHEL 9 kernel packages that remediate CVE-2025-38211 and several additional kernel vulnerabilities. The update affects RHEL 9 across x86_64, ARM64, s390x, and ppc64le, and requires a reboot after installation.
Red Hat issued Moderate-severity RHSA-2025:15009 for RHEL 8 Real Time Linux, Real Time for NFV, and x86_64 RHEL 8.10 Extended Life Cycle. Kernel-rt version 4.18.0-553.72.1.rt7.413.el8_10 fixes CVE-2025-38211 and CVE-2025-38464; systems require a reboot after installation.
Red Hat issued RHSA-2025:15008 for RHEL 8 and RHSA-2025:15005 for RHEL 10, providing kernel updates that remediate CVE-2025-38211, an RDMA/iwcm use-after-free involving work objects after cm_id destruction. The updates cover the listed supported architectures and require a reboot to take effect.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
10 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.