Red Hat released RHSA-2025:13598 for Red Hat Enterprise Linux 10, updating kernel packages to remediate seven Moderate-severity vulnerabilities across x86_64, aarch64, ppc64le, and s390x systems, including applicable Extended Update Support and lifecycle channels. The flaws include a double-free condition, memory-management races, out-of-bounds reads, invalid memory access, and hardware-related kernel issues.
Among the fixed issues, CVE-2025-38079 affects the AF_ALG algif_hash socket hash_accept path: a local low-privileged attacker may trigger a double free and slab use-after-free through accept(2) under a specific MSG_MORE and crypto_ahash_import failure condition, potentially causing memory corruption or code execution. CVE-2025-38084 fixes a hugetlb page-table race during virtual-memory-area splitting, while CVE-2025-38159 corrects an rtw88 Wi-Fi-driver out-of-bounds read that could disclose memory or crash the kernel; preventing the rtw88 module from loading is a temporary mitigation. Organizations should install the updated kernel and reboot affected RHEL 10 hosts.

See real exploitation activity before you spend the cycle.
15 events from the most recent confirmed update back to the earliest known activity.
Red Hat updated its RHEL 10 kernel security advisory RHSA-2025:13598.
Red Hat released RHSA-2025:13589 and RHSA-2025:13590, fixing the rtw88 out-of-bounds read in RHEL 8 kernel and kernel-rt packages.
Red Hat issued the Moderate-severity RHSA-2025:13598 kernel update for RHEL 10 across x86_64, aarch64, s390x, and ppc64le. It remediated seven kernel flaws, including CVE-2025-38079, CVE-2025-38084, and CVE-2025-38159, and required a reboot after installation.
Red Hat released RHSA-2025:12752 and RHSA-2025:12753 to fix CVE-2025-38079 in RHEL 8 kernel and kernel-rt packages.
Red Hat published CVE-2025-38159, an out-of-bounds read in the Linux kernel rtw88 Wi-Fi driver's Bluetooth/Wi-Fi coexistence handling. The upstream correction expands the para buffer from two to six bytes.
Red Hat published its record for CVE-2025-38079, a double-free flaw in the Linux kernel AF_ALG hash socket hash_accept path. The flaw can occur when crypto_ahash_import fails after accept(2) is called with MSG_MORE set, leading to a slab use-after-free condition.
Red Hat issued CVE-2025-38079 fixes for additional RHEL 8 and 9 SAP, telecommunications, extended-support, and update-service channels, including RHSA-2025:14511, 14691, 14696, 15016, 15658, and 15670. The source does not provide release dates for these advisories.
Red Hat addressed the hugetlb VMA-splitting page-table race condition tracked as CVE-2025-38084 for RHEL 9 through RHSA-2025:13962. The source does not state the release date of that advisory.
Red Hat released RHSA-2025:21667 to fix CVE-2025-38159 in the RHEL 8.2 Advanced Update Support kernel.
Red Hat released RHSA-2025:15660 to address CVE-2025-38159 for RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On.
Red Hat released RHSA-2025:15647 for RHEL 8.6 support channels and RHSA-2025:15649 for the RHEL 8.8 SAP Update Services channel, addressing CVE-2025-38159.
RHSA-2025:15035 fixed CVE-2025-38159 in the RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On kernel packages.
Red Hat released RHSA-2025:14986 and RHSA-2025:14987 for RHEL 7 Extended Lifecycle Support, and RHSA-2025:15035 for RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On.
Red Hat released RHSA-2025:14692 for RHEL 8.6 Advanced Mission Critical Update Support and Telecommunications Update Service, and RHSA-2025:14742 for RHEL 8.2 Advanced Update Support, addressing CVE-2025-38159.
Red Hat released fixes for CVE-2025-38079 through RHSA-2025:14742 for RHEL 8.2 Advanced Update Support and RHSA-2025:14692 for RHEL 8.6 Advanced Mission Critical Update Support, SAP Solutions, and Telecommunications Update Service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.