Red Hat issued Important kernel security updates for RHEL 9 and RHEL 10 that remediate CVE-2025-38089, a flaw in Linux SunRPC server authentication handling. A crafted RPC request can produce an SVC_GARBAGE result without initializing an acceptance-status pointer, potentially crashing a kernel thread on its first RPC request or causing memory corruption. The upstream correction maps the condition to AUTH_ERROR with AUTH_BADCRED, in line with RFC 5531.
RHSA-2025:11411 delivers the SunRPC fix for RHEL 9 across x86_64, ARM64, s390x, and ppc64le channels, alongside a uvcvideo dangling-pointer fix for CVE-2024-58002. RHSA-2025:11428 updates RHEL 10 kernels and addresses five vulnerabilities affecting uvcvideo, iwlwifi, huge_memory, and SunRPC components. Red Hat also fixed CVE-2022-49995, a writeback use-after-free that can occur after disk-device removal, in RHEL 9 SAP Update Services packages. Organizations should install the applicable kernel updates and reboot systems to activate the fixes.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat published the Important RHSA-2025:11428 kernel security advisory for RHEL 10. It remediates CVE-2024-58002, CVE-2024-57980, CVE-2025-21905, CVE-2025-37958, and CVE-2025-38089; a reboot is required for the updated kernel to take effect.
Red Hat published the Important RHSA-2025:11411 kernel security advisory for RHEL 9. The update fixes CVE-2024-58002 in uvcvideo and CVE-2025-38089 in SunRPC authentication processing; systems require a reboot after installation.
Red Hat released live kpatch-patch fixes for CVE-2025-38089 in RHSA-2025:12976 for applicable RHEL 9 streams and RHSA-2025:12977 for RHEL 9.4 Extended Update Support. These updates address the SunRPC authentication-processing flaw without requiring the standard kernel-update reboot path.
Red Hat addressed the Linux kernel writeback use-after-free vulnerability CVE-2022-49995 for RHEL 9.0 Update Services for SAP Solutions through RHSA-2025:12525 and RHSA-2025:12526.
The Linux kernel CVE team assigned CVE-2025-38089 for a remotely triggerable SunRPC server authentication-processing flaw that can cause a NULL-pointer kernel crash or memory scribble via a crafted RPC packet. Upstream fixes treat SVC_GARBAGE during authentication as an AUTH_ERROR and are available in Linux 6.6.95, 6.12.35, 6.15.4, and 6.16-rc3.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcelore.kernel.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.