Red Hat released kernel security updates for multiple RHEL 8.2, 8.8, 9.2, and 10 lifecycle, SAP, telecommunications, and extended-support offerings. The advisories address vulnerabilities including USB DWC3 gadget event-buffer bounds handling (CVE-2025-37810), SunRPC TLS-alert processing (CVE-2025-38566), VKMS/DRM use-after-free and double-free conditions (CVE-2025-22097), UDP memory-accounting leaks (CVE-2025-22058), RDMA/IWCM use-after-free (CVE-2025-38211), POSIX CPU-timer races (CVE-2025-38352), and a sch_qfq scheduler race (CVE-2025-38477). Additional fixes cover ext4 attributes, IPv6 multicast, MD RAID10, TIPC, Intel i40e MMIO access, vsock TOCTOU handling, netfilter conntrack removal, SMB oplocks, and DRM/GEM framebuffer references.
Affected organizations should deploy the applicable updated packages, including RHEL 9.2 kernel 5.14.0-284.137.1.el9_2, RHEL 9.2 real-time kernel 5.14.0-284.140.1.rt14.425.el9_2, and RHEL 8.2 AUS kernel 4.18.0-193.168.1.el8_2. The updates apply across supported x86_64, ARM64, ppc64le, and s390x offerings where listed; systems must be rebooted after installation for the patched kernel to become active.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-security advisory RHSA-2025:17123 for the RHEL 9.2 Real Time Linux Kernel in SAP Solutions and Extended Life Cycle offerings. Kernel-rt version 5.14.0-284.140.1.rt14.425.el9_2 remediates six vulnerabilities affecting USB DWC3, i40e, vsock, DRM/GEM, netfilter conntrack, and the SMB client; systems must be rebooted.
Red Hat issued Moderate-severity RHSA-2025:17009 for RHEL 8.8 update-service variants, delivering kernel-4.18.0-477.112.1.el8_8. It fixes CVE-2025-22097 in DRM/VKMS, CVE-2025-22058 in UDP accounting, and CVE-2025-38477 in the sch_qfq scheduler; a reboot is required.
Red Hat published Moderate-severity advisory RHSA-2025:16354 for RHEL 10 and applicable CodeReady Linux Builder repositories across x86_64, aarch64, s390x, and ppc64le. The update fixes CVE-2025-37810 in the USB DWC3 gadget driver and CVE-2025-38566 in SunRPC TLS-alert handling; affected systems must be rebooted.
Red Hat published Important-rated RHSA-2025:15669 for supported RHEL 9.2 update and lifecycle services. The 5.14.0-284.137.1.el9_2 kernel update fixes VKMS, UDP memory-accounting, RDMA/IWCM, and POSIX CPU-timer flaws and requires a reboot.
Red Hat issued Important-rated advisory RHSA-2025:15656 for RHEL Server 8.2 Advanced Update Support on x86_64. Kernel version 4.18.0-193.168.1.el8_2 fixes six issues, including flaws in ext4, IPv6 multicast, UDP accounting, MD RAID10, POSIX CPU timers, and TIPC; systems require a reboot after installation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.