Red Hat released an Important update, RHSA-2025:15786, for Red Hat Enterprise Linux 8 Real Time kernel packages to remediate three kernel flaws: CVE-2025-38350 in net/sched, CVE-2025-38392 in the IDPF driver control queue, and CVE-2025-38449 in DRM/GEM framebuffer-handle reference management. The advisory affects RHEL for Real Time 8, Real Time for NFV 8, and x86_64 Extended Life Cycle 8.10; the fixed package is kernel-rt-4.18.0-553.75.1.rt7.416.el8_10.
CVE-2025-38350 is a use-after-free in the Credit-Based Shaper (sch_cbs) queuing discipline. Improper reset handling can leave queue lengths inconsistent and trigger a use-after-free in a parent HFSC scheduler during interface resets. Red Hat rates the issue CVSS 7.0, while NVD and cve.org rate it 7.8; on RHEL 8 and later, non-root users may be able to exploit it through unprivileged user namespaces. Organizations should deploy the updated kernel packages and reboot affected hosts; where patching cannot occur promptly, prevent the sch_cbs module from loading.

See real exploitation activity before you spend the cycle.
15 events from the most recent confirmed update back to the earliest known activity.
Red Hat published Important advisory RHSA-2025:15786 for RHEL 8 kernel-rt packages, fixing CVE-2025-38350, CVE-2025-38392, and CVE-2025-38449. The update supplies kernel-rt version 4.18.0-553.75.1.rt7.416.el8_10 for affected Real Time, Real Time for NFV, and x86_64 ELS 8.10 systems.
Red Hat issued Important advisory RHSA-2025:15429 for RHEL 9 kernel packages, remediating the CVE-2025-37803 udmabuf buffer-size overflow and CVE-2025-38392 IDPF control-queue synchronization flaw. The update applies across RHEL 9 architectures and specified extended-support and SAP offerings, and requires a reboot after installation.
Red Hat issued RHSA-2025:15447 for RHEL 10 kernel packages, remediating CVE-2025-22097, a drm/vkms use-after-free and double-free condition, and CVE-2025-37803, a udmabuf buffer-size overflow. The Important advisory applies across supported RHEL 10 architectures and requires a reboot after installation.
Red Hat released RHSA-2025:15447 with a RHEL 10 kernel fix for CVE-2025-38449, a moderate-severity use-after-free flaw in the Linux kernel DRM/GEM subsystem that a local user could exploit to crash the kernel on affected DRI graphics systems.
Red Hat issued RHSA-2025:15447, providing kernel-package fixes for CVE-2025-38350 in Red Hat Enterprise Linux 10.
Red Hat released RHSA-2025:15035, addressing CVE-2025-38350 in kernel packages for RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On offerings.
Red Hat released RHSA-2025:14742 with kernel-package fixes for CVE-2025-38350 in Red Hat Enterprise Linux 8.2 Advanced Update Support.
Red Hat issued RHSA-2025:14746 and RHSA-2025:14748, fixing CVE-2025-38350 in kernel-rt and kernel packages for Red Hat Enterprise Linux 7 Extended Lifecycle Support.
Red Hat released RHSA-2025:14413, providing kernel-package fixes for CVE-2025-38350 in Red Hat Enterprise Linux 7.7 Advanced Update Support.
An upstream Linux CVE announcement described CVE-2025-22097, a DRM/VKMS initialization-error flaw in which vkms_exit() could access an uninitialized or freed default_config pointer and free it twice. The upstream fix defers default_config initialization until driver initialization succeeds.
The Linux kernel CVE team assigned CVE-2025-38350 to a use-after-free in net/sched/sch_api.c caused by stale class pointers after child qdiscs become empty during enqueue processing. Stable fixes make qdisc_tree_reduce_backlog() notify parent qdiscs whenever a child becomes empty, with fixed releases identified for multiple 5.4 through 6.16-rc kernel lines.
Red Hat released RHSA-2025:17958 to fix the Intel idpf driver local denial-of-service vulnerability CVE-2025-38392 in the RHEL 9.4 Extended Update Support kernel.
Red Hat released RHSA-2025:16582, providing a kpatch-patch update for Red Hat Enterprise Linux 8 to address CVE-2025-38350.
The Linux kernel CVE team assigned CVE-2025-38392 to an Intel IDPF driver control-queue locking flaw that can invoke a mutex from atomic context when MAC filtering is enabled. The fix replaces the control-queue mutex with a spinlock and uses contiguous DMA memory; fixed kernel releases include 6.12.37, 6.15.6, and 6.16-rc5.
The Linux kernel CVE team assigned CVE-2025-38449 to a DRM/GEM framebuffer reference-counting flaw where releasing a GEM handle can prematurely release its dma-buf backing object and cause a segmentation fault during later mode-setting operations. Fixes acquire GEM-handle references for framebuffer buffer objects and are included in Linux 6.6.99, 6.12.39, 6.15.7, and 6.16-rc5.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
12 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourcelore.kernel.org
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.