Red Hat released kernel-rt-4.18.0-553.64.1.rt7.405.el8_10 for Red Hat Enterprise Linux 8 Real Time, Real Time for NFV, and x86_64 Extended Life Cycle 8.10. The moderate-severity update remediates CVE-2025-21905, an out-of-bounds read in the Linux iwlwifi driver caused by logging firmware strings that may not be NUL-terminated; the condition could disclose memory contents or crash an affected system.
The advisory, RHSA-2025:11851, also fixes CVE-2025-21919, which can cause scheduler-related memory corruption, and CVE-2022-49977, an ftrace NULL-pointer dereference. Red Hat rated CVE-2025-21905 at CVSS 6.0 because exploitation in its products is local and requires high privileges, while NVD and CVE.org scored it 7.1. Administrators should apply the updated real-time kernel and reboot systems for the protections to take effect.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2025:11851 with kernel-rt 4.18.0-553.64.1.rt7.405.el8_10 for affected RHEL 8 real-time, NFV, and Extended Life Cycle deployments. The update fixes CVE-2025-21905, CVE-2025-21919 scheduler memory corruption, and CVE-2022-49977 ftrace NULL-pointer dereference; systems must be rebooted after installation.
Red Hat released RHSA-2025:11428 for Red Hat Enterprise Linux 10, providing a kernel fix for the iwlwifi out-of-bounds read vulnerability CVE-2025-21905.
Red Hat released RHSA-2025:13099 with kernel fixes for CVE-2025-21905 for RHEL 8.6 Advanced Mission Critical Update Support, Telecommunications Update Service, and Update Services for SAP Solutions.
Red Hat released RHSA-2025:13061 with a kernel fix for CVE-2025-21905 for the RHEL 8.8 Telecommunications Update Service stream.
Red Hat released RHSA-2025:12623 with a kernel fix for CVE-2025-21905 for Red Hat Enterprise Linux 8.2 Advanced Update Support.
Red Hat released RHSA-2025:12238 with a kernel fix for CVE-2025-21905 for RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On.
Red Hat released RHSA-2025:11850, providing a Red Hat Enterprise Linux 8 kernel fix for CVE-2025-21905.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.