Red Hat released Moderate-severity kernel updates for RHEL 9.2 SAP Solutions, associated Extended Update Support and Extended Life Cycle channels, addressing CVE-2023-52933 in Linux SquashFS. A corrupted filesystem image can supply an xattr_ids count of 4294967071, which is interpreted as -225 in a signed variable; resulting integer-overflow behavior can calculate a zero-length xattr index table and allow a corrupted xattr_table_start value to bypass a sanity check. The upstream fix uses unsigned handling for xattr_ids and safe u64 widening in metadata-size calculations, including on 32-bit systems.
RHSA-2025:11045 provides kernel version 5.14.0-284.125.1.el9_2, while RHSA-2025:10527 provides Real Time Kernel version 5.14.0-284.125.1.rt14.410.el9_2. Both advisories also remediate CVE-2022-49395, an out-of-bounds read in User-Mode Linux LDT setup. Administrators should install the applicable kernel packages and reboot affected systems to activate the fixes.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2025:11045 for RHEL 9.2 update-service and extended-life-cycle channels. Updated kernel-5.14.0-284.125.1.el9_2 packages remediate CVE-2023-52933 across supported architectures, with a reboot required for the fix to take effect.
Red Hat issued Moderate-severity advisory RHSA-2025:10527 for RHEL 9.2 SAP Solutions Update Services and Extended Life Cycle x86_64 subscriptions. The kernel-rt update, version 5.14.0-284.125.1.rt14.410.el9_2, fixes CVE-2023-52933 and requires a reboot after installation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.