Red Hat released updated Red Hat Enterprise Linux 9 and OpenShift Dev Spaces 3 container images incorporating kernel security fixes from RHSA-2025:2627. The refreshed images cover x86_64, ARM64, IBM Z (s390x), and little-endian Power (ppc64le) variants, including applicable EUS, ELS, AUS, and SAP offerings. Red Hat instructed customers to update image references in Dockerfiles and automation and rebuild all dependent container images.
The fixes include CVE-2024-50302, a Linux kernel HID-core vulnerability in which an uninitialized report buffer could expose kernel memory through a specially crafted HID report. The upstream remediation zero-initializes the buffer at allocation; the vulnerability was added to CISA's Known Exploited Vulnerabilities catalog. The advisories also backport fixes for additional kernel flaws involving null-pointer dereferences, use-after-free and dangling-pointer conditions, uninitialized buffers, and out-of-bounds access.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued RHBA-2025:3020 for OpenShift Dev Spaces 3 images on x86_64, ppc64le, and s390x. The update included backported RHSA-2025:2627 security fixes for seven listed CVEs, including CVE-2024-50302, and Red Hat advised customers to upgrade and rebuild dependent images.
Red Hat issued RHBA-2025:2783, updating RHEL 9 container images for x86_64, ARM64, s390x, and ppc64le. The images incorporated RHSA-2025:2627 backported fixes for six Linux kernel CVEs, including CVE-2024-50302; Red Hat advised users to upgrade and rebuild dependent images.
CISA added CVE-2024-50302 to its Known Exploited Vulnerabilities Catalog, indicating the Linux kernel HID-core issue was known to be exploited.
An upstream CVE announcement described the Linux kernel HID-core flaw CVE-2024-50302, in which an uninitialized HID report buffer could disclose kernel memory. The upstream remediation zero-initializes the buffer when it is allocated.
Red Hat addressed CVE-2024-50302 through security advisories for numerous RHEL 6, 7, 8, and 9 offerings and OpenShift Container Platform 4.12 through 4.18. The fixes included RHSA-2025:2473 through RHSA-2025:2646 and OpenShift advisories including RHSA-2025:2441, RHSA-2025:2701, and RHSA-2025:3301.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.