Red Hat released RHSA-2025:3021, a Moderate-severity kernel update for Red Hat Enterprise Linux 9.4 support channels. The update remediates six issues spanning RDMA SRP target initialization, ACPI extended logging, mlx5e aRFS handling, PCI power management, and memory-control-group concurrency. Affected deployments should install the applicable 5.14.0-427.60.1.el9_4 kernel packages and reboot to activate the new kernel.
The update includes the fix for CVE-2024-26872, in which the RDMA SRP target driver could register an event handler before an srpt device was fully initialized; upstream fixes defer registration until setup completes. It also carries the ACPI extlog code correction associated with CVE-2023-52605, a potential NULL-pointer dereference during cleanup that could cause a local denial of service, although that CVE was subsequently rejected upstream. The advisory applies across RHEL 9.4 x86_64, aarch64, ppc64le, and s390x channels, including EUS, ELS, AUS, SAP-related services, and associated CodeReady Linux Builder repositories.

See real exploitation activity before you spend the cycle.
10 events from the most recent confirmed update back to the earliest known activity.
Red Hat released RHSA-2024:7000 for the RHEL 8 kernel and RHSA-2024:7001 for the RHEL 8 kernel-rt package, addressing the ACPI extlog code issue associated with CVE-2023-52605.
Zack Miele reported CVE-2024-35835, a medium-severity double-free vulnerability in the Linux kernel net/mlx5e arfs_create_groups function. The Linux kernel CVE team assigned the identifier, and fixes were made available in multiple upstream kernel versions.
Robb Gatica reported a Linux kernel RDMA/srpt issue in which an event handler could be registered before the SRP target device was fully initialized. The Linux kernel CVE team assigned CVE-2024-26872.
The Linux CVE project rejected CVE-2023-52605 upstream, according to a Linux CVE announcement. Red Hat continued to track affected packages and fixes despite the rejection.
Red Hat published a record for CVE-2023-52605, describing a Linux kernel ACPI extlog NULL-pointer dereference that could cause local instability or denial-of-service crashes during cleanup.
Red Hat issued Moderate-severity advisory RHSA-2025:3021 for RHEL 9.4 support channels, providing kernel version 5.14.0-427.60.1.el9_4. The update addressed CVE-2023-52605, CVE-2024-26872, and four additional kernel vulnerabilities; systems require a reboot after installation.
Red Hat issued RHSA-2025:2627 to fix the RHEL 9 kernel issue associated with CVE-2023-52605.
A comment in Red Hat's CVE tracking record stated that CVE-2023-52605 had been rejected upstream.
Upstream Linux kernel releases 5.10.214, 5.15.153, 6.1.83, 6.6.23, 6.7.11, 6.8.2, and 6.9-rc1 incorporated a fix that defers srpt event-handler registration until device setup is complete.
The proposed change to move extlog_l1_addr dereferencing inside a NULL check was incorporated into stable Linux kernel versions 4.19.307, 5.4.269, 5.10.210, 5.15.149, 6.1.77, 6.6.16, 6.7.4, and 6.8-rc1.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourcelore.kernel.org
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcelore.kernel.org
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.