Red Hat released Important kernel security updates for Red Hat Enterprise Linux (RHEL) 9, RHEL 9 Real Time for SAP Solutions, and RHEL 10, addressing vulnerabilities in IPv6 multicast processing, ATM networking, OverlayFS, UDF, vmxnet3 XDP handling, AMD microcode interactions, and other kernel components. The affected issues include use-after-free, out-of-bounds read and write, and packet-processing flaws; RHEL 10 fixes include CVE-2025-21759, CVE-2025-21991, and CVE-2025-37799.
The RHEL 9 updates also remediate CVE-2022-49395, an out-of-bounds stack read in User-Mode Linux LDT initialization caused by a byte-count versus long-count mismatch, and CVE-2022-49846, a slab out-of-bounds write in UDF directory-entry processing. Updates apply across supported x86_64, ARM64, IBM Z, and Power architectures and relevant EUS, ELS, SAP, and CodeReady variants. Organizations should deploy the applicable updated kernel packages and reboot affected systems to activate the fixes.

See real exploitation activity before you spend the cycle.
6 events from the most recent confirmed update back to the earliest known activity.
Red Hat released an Important kernel-rt update for RHEL 9.0 SAP Solutions on x86_64, providing version 5.14.0-70.138.1.rt21.210.el9_0. It remediates ten kernel vulnerabilities affecting subsystems including User-Mode Linux, device mapper, IPv6 multicast, ATM, ext4, UDF, SquashFS, and the Atlantic driver.
Red Hat issued an Important RHEL 10 kernel update fixing CVE-2025-21759 in IPv6 multicast handling, CVE-2025-21991 involving AMD microcode and CPU-less NUMA nodes, and CVE-2025-37799 in vmxnet3 XDP processing.
Red Hat issued an Important RHEL 9 kernel update addressing five vulnerabilities, including IPv6 multicast, OverlayFS and ATM use-after-free flaws, the UDF out-of-bounds write, and vmxnet3 XDP packet sizing. The update applies across supported RHEL 9 architectures and related support offerings.
An upstream Linux kernel CVE advisory announced the resolution of CVE-2022-49846, a slab out-of-bounds write in the UDF filesystem function udf_find_entry().
Red Hat addressed CVE-2025-37799, a vmxnet3 XDP packet-sizing flaw that could expose uninitialized kernel memory and cause oversized-packet connectivity failures, in RHEL 9 through RHSA-2025:10674.
Red Hat remediated the Linux kernel OverlayFS use-after-free vulnerability CVE-2025-21887 in RHEL 10 through RHSA-2025:9079 and in RHEL 9.4 Extended Update Support through RHSA-2025:11810. The upstream fix delays dput(upper) until the upper dentry is no longer accessed by OverlayFS revalidation code.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
7 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.