Red Hat released RHSA-2026:1495 for the RHEL 9.0 Update Services for SAP Solutions kernel-rt stream, updating the Real Time Linux Kernel to 5.14.0-70.163.1.rt21.235.el9_0. The Important-rated update remediates 13 kernel vulnerabilities across networking, virtualization, storage, RDMA, audio, vsock, MPTCP, and graphics components, including CVE-2025-37803; systems must be rebooted after installation.
CVE-2025-37803 affects the Linux udmabuf driver’s udmabuf_create() function, where 32-bit page-limit arithmetic could overflow when deriving a limit from size_limit_mb. A local user with access to the udmabuf device could request unexpectedly large DMA-buffer allocations, potentially causing memory pressure or allocation failures; Red Hat rates the issue Moderate and does not assess it as network reachable or a direct memory-corruption condition. The upstream correction casts the value to u64, and fixes are available in stable kernels beginning with 5.4.293, 5.10.237, 5.15.181, 6.1.136, 6.6.89, and 6.14.5; upstream recommends updating to a current stable kernel rather than cherry-picking the patch.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated RHSA-2026:1495 for the RHEL 9.0 Update Services for SAP Solutions x86_64 Real Time Linux Kernel. The kernel-rt update to version 5.14.0-70.163.1.rt21.235.el9_0 remediates 13 kernel vulnerabilities and requires a reboot after installation.
Red Hat released RHSA-2025:11571 for the RHEL 9.2 Update Services for SAP Solutions kernel and RHSA-2025:11572 for its kernel-rt stream, addressing CVE-2025-37803.
The Linux kernel CVE team disclosed CVE-2025-37803, a buffer-size integer overflow in the udmabuf driver's page-limit calculation during udmabuf creation. Fixed stable releases included 5.4.293, 5.10.237, 5.15.181, 6.1.136, 6.6.89, 6.14.5, and 6.15-rc2; users were advised to update rather than cherry-pick the fix.
Red Hat released RHSA-2025:15429 for RHEL 9 and RHSA-2025:15447 for RHEL 10, remediating the udmabuf integer-overflow vulnerability CVE-2025-37803.
Red Hat released RHSA-2025:11810, addressing CVE-2025-37803 in the Red Hat Enterprise Linux 9.4 Extended Update Support kernel stream.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
6 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.