Red Hat released Important kernel security updates for RHEL 7.7 Advanced Update Support, RHEL 8 Real Time/NFV and 8.10 Extended Life Cycle, and RHEL 9.0 Update Services for SAP Solutions. The updates remediate an uninitialized HID report-buffer flaw (CVE-2024-50302), a use-after-free in CAN BCM processing (CVE-2023-52922), and out-of-bounds access risks in ALSA USB-audio support for Extigy and Mbox devices (CVE-2024-53197).
The RHEL 8 kernel-rt update also fixes CVE-2024-57979, a PPS subsystem use-after-free that can occur when a PPS source is unregistered while character-device operations remain open, potentially causing memory corruption and kernel panic. Organizations should deploy the applicable fixed packages—including kernel-rt-4.18.0-553.44.1.rt7.385.el8_10, kernel-3.10.0-1062.93.1.el7, or kernel-rt-5.14.0-70.125.1.rt21.197.el9_0—and reboot affected hosts to activate the patched kernel; the advisories do not report known in-the-wild exploitation.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Important-rated RHSA-2025:2512 for the RHEL 9.0 Update Services for SAP Solutions real-time kernel. The update supplied kernel-rt 5.14.0-70.125.1.rt21.197.el9_0 and fixed CVE-2024-50302, CVE-2023-52922, and CVE-2024-53197.
Red Hat released Important-rated RHSA-2025:2514 for RHEL Server 7.7 Advanced Update Support on x86_64, providing kernel version 3.10.0-1062.93.1.el7. It remediated CVE-2024-50302, CVE-2023-52922, and CVE-2024-53197.
Red Hat issued Important-rated RHSA-2025:2474 for RHEL 8 Real Time, Real Time for NFV, and RHEL 8.10 ELS systems. The kernel-rt 4.18.0-553.44.1.rt7.385.el8_10 update fixed CVE-2024-50302, CVE-2024-53197, CVE-2024-57807, and the PPS use-after-free CVE-2024-57979.
Red Hat issued Important-rated RHSA-2025:1254 for RHEL 9.0 Update Services for SAP Solutions on x86_64. The kernel-rt 5.14.0-70.124.1.rt21.196.el9_0 update fixed CVE-2024-53104 in uvcvideo and CVE-2024-53113, a NULL-pointer dereference in alloc_pages_bulk_noprof.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.