Red Hat released Important kpatch/live-patch updates for supported Red Hat Enterprise Linux 8 and 9 systems, including SAP, EUS, AUS, ELC, telecommunications, and mission-critical variants. The advisories remediate five Linux kernel vulnerabilities in the HFSC network scheduler and DesignWare I2C driver, including the HFSC use-after-free issue tracked as CVE-2025-37890, reentrant enqueue behavior, queue-length-accounting and empty-child-notification defects, and CVE-2025-38380.
CVE-2025-38380 stems from incomplete initialization in the AMD-specific amd_i2c_dw_xfer_quirk() routine: msg_write_idx was not initialized before i2c_dw_xfer_init() ran, potentially causing an out-of-bounds access to I2C message data. Updates cover RHEL 8 kernel 4.18.0-553.16.1.el8_10 and RHEL 9 kernel 5.14.0-570.17.1.el9_6, plus specified RHEL 9 SAP kernel builds, on x86_64 and ppc64le. Organizations should deploy the applicable kpatch packages and reboot affected hosts for the fixes to take effect.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important advisory RHSA-2025:16580 for RHEL 8.6 kpatch packages serving Update Services for SAP Solutions and Extended Life Cycle Long Life systems. The update remediates CVE-2025-38380 and four HFSC scheduler flaws, including CVE-2025-37890, and requires a reboot to take effect.
Red Hat issued Important advisories RHSA-2025:16538, RHSA-2025:16541, RHSA-2025:16582, and RHSA-2025:16583, providing kpatch live-kernel updates for supported RHEL 8 and RHEL 9 offerings, including SAP-related subscriptions. The updates remediate CVE-2025-38380 alongside four HFSC network-scheduler vulnerabilities, and Red Hat stated that affected systems must be rebooted for the updates to take effect.
An upstream Linux CVE announcement disclosed CVE-2025-38380, an initialization flaw in the DesignWare I2C driver. The AMD-specific transfer quirk left msg_write_idx uninitialized, potentially enabling an out-of-bounds access to msgs; the upstream fix initializes the field before i2c_dw_xfer_init().
An upstream Linux CVE announcement disclosed CVE-2025-37890, a use-after-free vulnerability in the HFSC scheduler when a class uses a netem child queuing discipline. Netem packet duplication could cause reentrant duplicate insertion into HFSC timing trees; the upstream fix uses the n_active variable to prevent the duplicate insertion.
Red Hat issued Important advisory RHSA-2024:0386, providing kpatch-patch live-kernel updates for RHEL 9.0 Extended Update Support and associated SAP offerings on x86_64 and ppc64le. The update remediates HFSC use-after-free CVE-2023-4623, NVMe TCP crypto cleanup use-after-free CVE-2023-5178, and Intel IGB buffer-size flaw CVE-2023-45871.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
13 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.