Red Hat released Important Linux kernel updates for Red Hat Enterprise Linux 9 to remediate multiple security flaws, including CVE-2025-38052, a use-after-free read in the TIPC networking subsystem. The flaw occurs when asynchronous encryption work accesses TIPC cryptographic state after it has been freed during network-namespace deletion; the upstream fix preserves a network-namespace reference until encryption processing finishes.
The RHSA-2025:12746 update also addresses other kernel use-after-free issues, an integer-overflow vulnerability in CIFS processing, and an information-disclosure flaw in VMware VMCI datagram handling. Affected RHEL 9 systems include x86_64, ARM64, IBM Z, and Power little-endian deployments across standard, EUS, ELS, SAP, AUS, and CodeReady Linux Builder offerings; Red Hat also issued fixes for CVE-2025-38052 in supported RHEL 8 and RHEL 10 variants. Organizations should apply the appropriate kernel updates and reboot systems for the fixes to take effect.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHSA-2025:16045, an Important security advisory providing kpatch live-patch packages for RHEL 8.6 Update Services for SAP Solutions and applicable Extended Life Cycle Long Life deployments. The update remediates CVE-2025-38052 and CVE-2025-38352 for x86_64 and ppc64le systems.
Red Hat issued RHSA-2025:15933, an Important security advisory providing kpatch live-patch modules for RHEL 9.0 Update Services for SAP Solutions. The update remediates CVE-2025-38052 and CVE-2025-38352 for x86_64 and ppc64le systems across several 5.14.0-70 kernel builds.
Red Hat issued RHSA-2025:16008, an Important security advisory providing kpatch live-patch packages for RHEL 8.8 Update Services for SAP Solutions. The update remediates CVE-2025-38052 and CVE-2025-38352 for x86_64 and ppc64le systems, including applicable Extended Life Cycle offerings.
Red Hat issued RHSA-2025:15931, an Important security advisory providing kpatch live-patch updates for RHEL 9.2 SAP Update Services, AUS, and Extended Life Cycle offerings. The update remediates CVE-2025-38052 and CVE-2025-38352 for x86_64 and ppc64le systems.
Red Hat issued RHSA-2025:15932, an Important security advisory providing kpatch live-patch modules for RHEL 9.4 kernel builds. The update remediates CVE-2025-38052 and CVE-2025-38352 for x86_64 and ppc64le RHEL 9.4 EUS, AUS, SAP Update Services, and Extended Life Cycle offerings.
Red Hat issued RHSA-2025:15798, an Important RHEL 9 security advisory providing updated kpatch live-patch modules for CVE-2025-38052 and the POSIX CPU-timer race CVE-2025-38352. The update covers x86_64 and ppc64le RHEL 9 offerings, including EUS, ELS, AUS, and SAP variants.
Red Hat issued RHSA-2025:12746, an Important RHEL 9 kernel security update addressing multiple flaws, including CVE-2025-38052 and several use-after-free vulnerabilities. The update applies to supported RHEL 9 architectures and offerings, and Red Hat required systems to reboot after installation for the fixes to take effect.
Syzbot reported CVE-2025-38052, a slab use-after-free read in the Linux kernel TIPC asynchronous encryption-completion handler tipc_aead_encrypt_done. The upstream fix retains a network-namespace reference so TIPC crypto state cannot be freed before deferred encryption work completes.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
9 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.