Red Hat released updated Linux kernel and real-time kernel packages for supported RHEL 8 and RHEL 9 service streams to remediate CVE-2025-38464 and CVE-2025-38085. CVE-2025-38464 is a use-after-free in TIPC topology-server connection teardown: a race between tipc_topsrv_stop() and receive-work handling can release a connection’s final reference before tipc_conn_close() completes. CVE-2025-38085 affects hugetlb memory management, where a race between huge_pmd_unshare() and GUP-fast can cause a page-table walk to traverse another process’s page tables; upstream reported no immediate kernel-memory-corruption path.
The fixes retain TIPC connection references through close processing and synchronize removal of shared huge-page tables with an IPI. Affected offerings include RHEL 8.4, 8.8, 8.10 and RHEL 9.2 variants, including SAP, telecommunications, AUS, EUS, ELC, and Real Time deployments; examples include kernel 4.18.0-477.108.1.el8_8, 4.18.0-305.172.1.el8_4, and 5.14.0-284.136.1.el9_2. Administrators should apply the applicable Red Hat security updates and reboot systems to load the patched kernel.

See real exploitation activity before you spend the cycle.
20 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2025:15660 for RHEL 8.4 AUS and Extended Life Cycle Long Life systems. The Important-rated update provided kernel 4.18.0-305.172.1.el8_4 and remediated CVE-2025-38085 and CVE-2025-38464.
RHSA-2025:15658 updated the RHEL 9.0 SAP Solutions kernel-rt package to version 5.14.0-70.146.1.rt21.218.el9_0. The advisory fixed CVE-2025-38085 and CVE-2025-38464 among multiple kernel vulnerabilities.
Red Hat issued RHSA-2025:15647 for supported RHEL 8.6 service variants, including ELS/Long Life, AUS, TUS, and SAP Solutions. The update provided kernel 4.18.0-372.160.1.el8_6 and fixed both vulnerabilities.
Red Hat issued RHSA-2025:15224 and RHSA-2025:15227 for RHEL 9.2, remediating CVE-2025-38085 and CVE-2025-38464 in kernel-rt and standard kernel packages, respectively. The updates covered SAP Solutions, AUS, and Extended Life Cycle offerings.
Red Hat released RHSA-2025:15005 for the RHEL 10 kernel and RHSA-2025:15008 and RHSA-2025:15009 for standard RHEL 8 kernel and kernel-rt packages, remediating CVE-2025-38464. The flaw is a TIPC use-after-free that can allow a low-privileged local user to cause a kernel crash where user and network namespaces are enabled.
RHSA-2025:14985 updated RHEL 8.8 kernel packages for SAP Solutions and Telecommunications Update Service deployments, fixing CVE-2025-38085 and CVE-2025-38464. Red Hat supplied kernel version 4.18.0-477.108.1.el8_8.
Red Hat issued Moderate-rated RHSA-2025:14094 for RHEL 9.0 Update Services for SAP Solutions on x86_64. The kernel-rt 5.14.0-70.142.1.rt21.214.el9_0 update remediated eight vulnerabilities, including CVE-2025-21727, CVE-2025-21991, CVE-2025-22020, CVE-2025-37797, and CVE-2025-38086; a reboot is required.
Red Hat published RHSA-2025:13962, an Important RHEL 9 kernel security update that remediated CVE-2025-38085 alongside eight other CVEs across supported architectures and service offerings.
Red Hat issued RHSA-2025:13590 for RHEL 8 kernel-rt packages, fixing CVE-2025-38085 and other kernel flaws. The advisory supplied kernel-rt 4.18.0-553.69.1.rt7.410.el8_10 and required a reboot after installation.
Red Hat released RHSA-2025:13598 for the RHEL 10 kernel and RHSA-2025:13589 for the standard RHEL 8 kernel, remediating CVE-2025-38085. These advisories expanded fixes beyond the RHEL 8 kernel-rt update already recorded.
Red Hat issued Important advisory RHSA-2025:13029 for RHEL 9.0 Update Services for SAP Solutions on x86_64. The kernel-rt 5.14.0-70.141.1.rt21.213.el9_0 update fixed five flaws, including CVE-2025-38052 in TIPC, and requires affected systems to be rebooted.
Red Hat issued Moderate-rated RHSA-2025:12525 for RHEL 9.0 Update Services for SAP Solutions on x86_64. The kernel-rt 5.14.0-70.140.1.rt21.212.el9_0 update fixed six flaws, including CVE-2024-57980, CVE-2025-21905, CVE-2025-22113, CVE-2025-23150, CVE-2025-37958, and CVE-2022-49995, and requires affected systems to be rebooted.
Red Hat issued Important advisory RHSA-2025:12311 for RHEL 9.2 SAP Solutions and Extended Life Cycle x86_64 deployments. The kernel-rt 5.14.0-284.128.1.rt14.413.el9_2 update fixed seven Linux kernel vulnerabilities, including CVE-2025-38052, and requires affected systems to be rebooted.
Red Hat issued Important advisory RHSA-2025:12209 for RHEL 9.2 Update Services for SAP Solutions, delivering kernel-5.14.0-284.128.1.el9_2. The update fixed multiple flaws including CVE-2025-21759, CVE-2024-57980, CVE-2025-37958, and CVE-2025-38052, and requires affected systems to be rebooted.
An upstream Linux CVE announcement disclosed CVE-2025-38464, a use-after-free in TIPC topology-server connection teardown. The fix retains a tipc_conn reference before releasing the IDR lock and drops it after tipc_conn_close() completes.
An upstream Linux CVE announcement described CVE-2025-38085, a race in mm/hugetlb where huge_pmd_unshare() can allow concurrent GUP-fast traversal of another process's page tables. The remediation adds a broadcast IPI through tlb_remove_table_sync_one().
An upstream Linux CVE announcement disclosed CVE-2025-21759, in which igmp6_send() could access a network namespace pointer without RTNL or RCU protection, creating a potential use-after-free condition. The fix extends RCU protection, charges the IPv6 IGMP socket while protected, and uses alloc_skb() for the GFP_KERNEL socket allocations.
Red Hat documented CVE-2025-22020, a slab use-after-free in the Linux memstick rtsx_usb_ms driver's removal path, where queued poll work can access a freed memstick host during USB-device removal. Red Hat resolved the issue across affected RHEL 8, 9, and 10 streams through advisories including RHSA-2025:12662, RHSA-2025:12746, RHSA-2025:12752, and RHSA-2025:12753.
Red Hat documented CVE-2025-21727, a Linux kernel padata_reorder use-after-free caused by algorithm deletion freeing a padata object before padata_find_next accesses it. The upstream fix adds synchronize_rcu() to padata_free_shell, and Red Hat addressed the flaw through advisories for RHEL 8, 9, and 10 service variants.
Red Hat tracked CVE-2021-47670 as Bug 2360786, a medium-severity use-after-free in the Linux CAN peak_usb driver caused by accessing skb-backed data after peak_usb_netif_rx_ni(). Red Hat remediated it through multiple RHEL 8 advisories, including RHSA-2025:13589, RHSA-2025:13590, RHSA-2025:14136, RHSA-2025:14511, RHSA-2025:14692, and RHSA-2025:15035.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
28 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.