Red Hat released Moderate-severity advisory RHSA-2025:14438 for Red Hat Enterprise Linux 8 kernel packages, remediating CVE-2025-38200 and CVE-2025-22058. CVE-2025-38200 affects the Linux kernel's Intel i40e network driver: crafted device input can trigger an integer underflow in i40e_clear_hw, causing an MMIO write to an invalid page. Red Hat rates the flaw at CVSS 7.0, while NVD assigns 5.5.
Updated kernels are available for RHEL 8 on x86_64, s390x, ppc64le, and aarch64, including applicable Extended Life Cycle 8.10 and CodeReady Linux Builder repositories. The same advisory also fixes a UDP memory-accounting leak tracked as CVE-2025-22058. Organizations should apply the relevant kernel updates and reboot affected systems, as the fixes do not take effect until restart.

See real exploitation activity before you spend the cycle.
10 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2025:14439 for RHEL 8 kernel-rt packages, remediating CVE-2025-22058. The update provides kernel-rt version 4.18.0-553.71.1.rt7.412.el8_10 for Real Time 8, Real Time for NFV 8, and x86_64 Extended Life Cycle 8.10; a reboot is required.
Red Hat published Moderate-severity advisory RHSA-2025:14438, providing RHEL 8 kernel version 4.18.0-553.71.1.el8_10 and fixing CVE-2025-38200 as well as CVE-2025-22058. The update applies to multiple architectures and requires a reboot to take effect.
Red Hat remediated CVE-2025-38200 for the Red Hat Enterprise Linux 10 kernel through advisory RHSA-2025:14510.
CVE-2025-38200, an integer-underflow vulnerability in the Linux kernel i40e driver's i40e_clear_hw function, was publicly disclosed. A device can trigger an MMIO write to an invalid page through specially crafted input.
Red Hat published the CVE-2025-22058 record for an integer-overflow flaw in Linux kernel UDP socket receive-memory accounting. A local low-privileged application can set SO_RCVBUF to INT_MAX and potentially trigger memory-accounting errors during socket closure.
Red Hat issued RHSA-2025:22752 to fix CVE-2025-38200 for RHEL 8.4 Advanced Mission Critical Update Support and the RHEL 8.4 Extended Update Support Long-Life Add-On.
Red Hat remediated CVE-2025-38200 for the RHEL 8.2 Advanced Update Support stream through RHSA-2025:21667.
Red Hat released an additional RHEL 10 kernel remediation for CVE-2025-38200 through RHSA-2025:20095.
Red Hat issued RHSA-2025:17161 to fix the RHEL 7 Extended Lifecycle Support kernel package. It also issued RHSA-2025:17124 for RHEL 8.6 Advanced Mission Critical Update Support and Telecommunications Update Service streams.
Red Hat fixed CVE-2025-38200 in the Red Hat Enterprise Linux 7 Extended Lifecycle Support kernel-rt package through RHSA-2025:17109.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.