Red Hat released Moderate-severity kernel security updates for supported Red Hat Enterprise Linux 8 and 9 update-service, extended-support, SAP, and specialized deployment channels. The updates remediate memory-safety and reliability flaws across ext4, Intel iwlwifi, MD RAID, CIFS, ATM, media, RDMA, networking, memory management, and net-scheduling code, including use-after-free, double-free, out-of-bounds read, overflow, and uninitialized-access conditions. Affected ext4 issues include unsafe processing of extended attributes beyond valid boundaries (CVE-2025-37738 and CVE-2025-22121) and a journal-destruction race that can cause a kernel failure during unmount (CVE-2025-22113).
Other fixes limit an unterminated firmware-provided string in the iwlwifi driver (CVE-2025-21905), prevent invalid transparent-huge-page migration-entry dereferencing (CVE-2025-37958), validate Clause 45 MDIO PHY addresses (CVE-2025-38110), and correct an MD RAID5 use-after-free (CVE-2022-50022). Administrators should install the kernel build designated for their exact RHEL release and entitlement channel—examples include 4.18.0-305.165.1.el8_4, 4.18.0-372.155.1.el8_6, and 5.14.0-70.140.1.el9_0—then reboot affected systems to activate the fixes. Red Hat's advisory for the RHEL 8.2 AUS update did not report known exploitation in the wild.

See real exploitation activity before you spend the cycle.
26 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2025:13805 for RHEL 8.4 AUS and Extended Update Support Long-Life Add-On on x86_64. Kernel version 4.18.0-305.168.1.el8_4 fixed CVE-2025-23150, CVE-2022-50020, and CVE-2025-38086.
Red Hat issued Moderate-severity advisory RHSA-2025:13099 for selected RHEL 8.6 extended-support, SAP, and telecommunications offerings. Kernel version 4.18.0-372.155.1.el8_6 fixed CVE-2025-21905 and CVE-2025-37738.
Red Hat issued Moderate-severity advisory RHSA-2025:12623 for RHEL Server AUS 8.2 on x86_64. Kernel version 4.18.0-193.162.1.el8_2 fixed five vulnerabilities, including CVE-2025-21905, CVE-2025-37738, and CVE-2022-50022.
Red Hat issued Moderate-severity advisory RHSA-2025:12526 for RHEL 9.0 Update Services for SAP Solutions and related four-year update offerings. Kernel build 5.14.0-70.140.1.el9_0 remediated six vulnerabilities, including CVE-2025-21905, CVE-2025-22113, and CVE-2025-37958.
Red Hat issued Moderate-severity advisory RHSA-2025:12238 for RHEL 8.4 AUS and Extended Update Support Long-Life Add-On systems on x86_64. Kernel version 4.18.0-305.165.1.el8_4 fixed five flaws, including CVE-2025-21905, CVE-2025-37738, and CVE-2022-50022.
Red Hat issued Moderate-severity advisory RHSA-2025:11861 for RHEL 9 kernel deployments across supported architectures and update channels. The update remediated ten kernel vulnerabilities, including CVE-2025-21905, CVE-2025-22113, CVE-2025-22121, CVE-2025-37958, CVE-2025-38086, and CVE-2025-38110.
Red Hat issued Important-severity advisory RHSA-2025:11428 for RHEL 10 and CodeReady Linux Builder 10 across supported architectures. The kernel update fixed five described vulnerabilities, including CVE-2024-58002, CVE-2024-57980, CVE-2025-21905, CVE-2025-37958, and CVE-2025-38089; Red Hat required a reboot after installation.
Red Hat issued Important-severity advisory RHSA-2025:10675 for Real Time Linux Kernel deployments on RHEL 9.2 SAP Solutions and Extended Life Cycle x86_64 systems. Kernel-rt version 5.14.0-284.124.1.rt14.409.el9_2 fixed CVE-2023-1652, CVE-2025-37738, CVE-2022-49846, and CVE-2022-50066; affected systems require a reboot.
An upstream Linux CVE announcement was referenced for CVE-2025-38110. The flaw allowed unvalidated Clause 45 MDIO addresses to cause out-of-bounds access to mdiobus statistics, and was fixed by validating the address before operations.
An upstream Linux CVE announcement was published for CVE-2022-50022, a potential use-after-free in the MD RAID5 driver. The fix moves raid5_release_stripe() to the end of the affected function to prevent later access to a potentially freed object.
An upstream Linux CVE announcement was published for CVE-2025-37738, a slab use-after-free in ext4 extended-attribute cleanup. The remediation makes ext4 ignore xattr entries beyond the valid end boundary.
An upstream Linux CVE announcement was published for CVE-2025-22121, an ext4 out-of-bounds read/use-after-free condition in extended-attribute cleanup. The fix validates inode-resident extended attributes before they are processed.
The OSIDB entry for CVE-2025-21905 was recorded. The flaw could let the iwlwifi driver read beyond a firmware TLV buffer when printing a non-NUL-terminated firmware-provided string.
Red Hat issued Moderate-severity advisory RHSA-2025:1658 for RHEL 9.4 Extended Update Support and associated update-service channels. Kernel version 5.14.0-427.55.1.el9_4 remediated 16 described vulnerabilities affecting RAID5, nftables, swap, device-tree parsing, SELinux/Smack, XFRM, IPv6 handling, ARM64 SVE, and other components; Red Hat required a reboot after installation.
Red Hat released RHSA-2024:4823 and RHSA-2024:4831 for RHEL 9.2 Extended Update Support kernel and kernel-rt packages, remediating the ext4 double-free flaw CVE-2024-26704. Red Hat subsequently issued fixes for additional RHEL 8 and RHEL 9 product streams through 2024 errata.
Red Hat issued RHSA-2024:4211 to fix Moderate-severity iwlwifi debug-TLV vulnerability CVE-2024-35845 in RHEL 8 kernel packages. The flaw could cause denial of service when a privileged local user enabled iwlwifi debug mode; Red Hat advised blacklisting the iwlwifi module when patching was not possible.
Red Hat issued RHBA-2024:3990 for updated RHOSE ASYNC - AUTO container images used with OpenShift Container Platform 4.12 for RHEL 8 on x86_64. The images backport fixes from RHSA-2024:3618 for numerous kernel vulnerabilities, including CVE-2024-23307, and Red Hat advised users to upgrade the images and rebuild dependent containers.
Rohit Keshri reported CVE-2024-36921, an invalid station (STA) ID handling flaw in the Intel iwlwifi MVM driver during station removal. The upstream fix adds a guard against invalid STA IDs, and fixes were included in Linux kernel versions 6.6.31, 6.8.10, and 6.9.
The Linux kernel CVE team announced CVE-2024-35845 for an iwlwifi debug-TLV flaw caused by failure to ensure NUL termination. Red Hat later remediated the issue through advisories affecting RHEL 8, RHEL 9, and selected EUS and specialized RHEL offerings.
Zack Miele reported CVE-2024-27434, an iwlwifi MVM Wi-Fi driver issue involving incorrect setting of the MFP flag for the GTK. The Linux kernel CVE team assigned the CVE; fixes were listed in kernel versions 6.6.23, 6.7.11, 6.8.2, and 6.9.
The Linux kernel CVE team assigned CVE-2024-26704 to an ext4 vulnerability in which an incorrect extents moved_len value could cause a double-free of blocks. The issue was resolved upstream by the fix titled "ext4: fix double-free of blocks due to wrong extents moved_len."
Marco Benatto reported CVE-2024-26610, a medium-severity memory-corruption vulnerability in the Linux kernel iwlwifi Wi-Fi driver. The issue was fixed upstream in kernels 5.10.210, 5.15.149, 6.1.76, 6.6.15, 6.7.3, and 6.8-rc2, and Red Hat addressed it for RHEL 8 through RHSA-2024:3618 and RHSA-2024:3627.
Rohit Keshri reported CVE-2024-23307, an integer-overflow or wraparound flaw in the Linux kernel's RAID5 raid5_cache_count function affecting the md, raid, and raid5 modules. Red Hat tracked it as Bug 2267705 and classified it as medium severity; advisories later addressed it for RHEL 8, RHEL 9, and RHEL 9.4 EUS.
Red Hat documented CVE-2024-36922, an iwlwifi driver flaw caused by reading the transmit-queue read pointer, txq->read_ptr, without the required lock. The upstream fix reads the pointer while holding the lock; Red Hat addressed it through RHSA-2024:5363, RHSA-2024:5364, RHSA-2024:5365, and RHSA-2024:7000 for affected RHEL 8 and 9 offerings.
Red Hat documented CVE-2024-40929 in the iwlwifi MVM Wi-Fi driver, where SSID data could be accessed while n_ssids was zero, resulting in an out-of-bounds memory access. The issue was fixed by validating n_ssids before SSID-pointer access and addressed through RHSA-2024:5928 for RHEL 9 and RHSA-2024:7000 and RHSA-2024:7001 for RHEL 8.
Red Hat documented CVE-2024-58002, in which pending asynchronous uvcvideo controls could retain dangling pointers to file handles after their descriptors were closed. The kernel fix clears pending pointers during release(), and Red Hat identified remediation advisories across RHEL 8, 9, and 10, including extended-support and specialized variants.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
31 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.