Red Hat released kernel security updates for multiple RHEL 8.4, 9/9.4, and 10.0 support channels, addressing vulnerabilities in networking, NFS, USB audio, Wi-Fi, Bluetooth, storage, cryptography, EFI handling, and speculative-execution mitigations. The advisories include builds 4.18.0-305.182.1.el8_4 for RHEL 8.4 AUS and long-life systems, 5.14.0-427.100.1.el9_4 for RHEL 9.4, and 6.12.0-55.52.1.el10_0 for RHEL 10.0 Extended Update Support and related channels.
Among the fixed issues is CVE-2025-39697, a Moderate-severity NFS write-path use-after-free race that an authenticated client with write access to an NFS export could exploit through carefully timed concurrent writes to crash the kernel, causing remote denial of service. Updates also remediate the ALSA USB-audio out-of-bounds flaw CVE-2022-48701 and other bounds-checking, use-after-free, and protocol-handling defects; Red Hat advises customers to reboot after installation so the patched kernel is loaded. Disabling automatic loading of the NFS kernel module can reduce exposure to CVE-2025-39697 where NFS is not required.

See real exploitation activity before you spend the cycle.
21 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued the Moderate RHSA-2026:0271 kernel update for RHEL 10.0 Extended Update Support and related channels. The kernel 6.12.0-55.52.1.el10_0 update fixes eight vulnerabilities, including CVE-2025-40300 and several out-of-bounds and use-after-free flaws; systems require a reboot.
Red Hat issued the Important RHSA-2025:23463 kernel update for RHEL 8.4 AUS and Extended Life Cycle Long-Life Add-On systems. Kernel 4.18.0-305.182.1.el8_4 remediates 14 vulnerabilities across networking, USB audio, Bluetooth, storage, RDMA, NFS, SCTP, and TCP components.
Red Hat released the Moderate RHSA-2025:21760 update for RHEL 9.4 support channels, providing kernel 5.14.0-427.100.1.el9_4 and fixing nine CVEs, including the NFS race CVE-2025-39697 and VMSCAPE mitigation CVE-2025-40300.
Red Hat released the Moderate RHSA-2025:21112 kernel update for RHEL 9, fixing 13 vulnerabilities including CVE-2025-39697, CVE-2025-40300, and flaws in SunRPC, virtio-vsock, EFI, Wi-Fi, SCSI, and cryptographic components.
RHSA-2025:19106 released fixed RHEL 10 kernel packages for the NFS write-path race condition tracked as CVE-2025-39697.
Red Hat issued Moderate-severity advisory RHSA-2025:17776 for RHEL 10 kernel packages, fixing HID core CVE-2025-38556, ath12k Wi-Fi CVE-2025-39761, and ALSA USB-audio CVE-2025-39757. The update affects RHEL 10 and CodeReady Linux Builder deployments across supported architectures and requires a reboot after installation.
Red Hat issued Moderate-severity advisory RHSA-2025:17760 for RHEL 9 kernel packages, fixing four vulnerabilities in HID core, eventpoll, ALSA USB audio, and the seqiv crypto component. The update applies across RHEL 9 support streams and requires a reboot after installation.
Red Hat published its record for CVE-2025-39697, a Moderate NFS write-path use-after-free race that can allow an NFS client with write access to crash a kernel and cause remote denial of service.
Linux upstream published the CVE-2025-38614 announcement for a semi-unbounded recursion vulnerability in eventpoll (epoll) instance graphs. The flaw could permit graph recursion to roughly 500 levels; the fix enforces EP_MAX_NESTS path limits using improved subtree and upward-depth checks.
Red Hat issued Moderate-severity advisory RHSA-2025:3935 for RHEL 9.4 update channels, providing kernel 5.14.0-427.65.1.el9_4. The update fixes 13 CVEs affecting networking, Wi-Fi, storage, virtualization, NFS, interrupt-controller, and USB-audio components and requires a reboot.
Red Hat tracked CVE-2024-50192, a medium-severity Linux irqchip/gic-v4 race in which userspace could request a VPE affinity change after the VPE was unmapped while its doorbell interrupt remained visible. The upstream fix checks vmapp_count and rejects VMOVP operations when the VPE is no longer mapped.
The Linux kernel upstream advisory announced CVE-2022-48701, an out-of-bounds vulnerability in the ALSA USB-audio __snd_usb_parse_audio_interface() function.
Red Hat Bugzilla recorded CVE-2024-27048, a medium-severity flaw in the Broadcom brcm80211 Wi-Fi driver caused by improper handling of a pmk_op allocation failure. Red Hat later addressed it through RHEL 8, RHEL 9, and RHEL 9.4 EUS kernel advisories.
Marco Benatto reported CVE-2024-26614, a Linux kernel TCP issue involving initialization of accept_queue spinlocks. Red Hat tracked the issue as low severity under bug 2269211; fixes were later provided upstream, in Fedora stable kernels, and through RHEL 8 and RHEL 9 advisories.
Zack Miele reported Red Hat Bug 2267916 for CVE-2021-47101, a low-severity uninitialized-value flaw in the Linux ASIX USB Ethernet driver's asix_mdio_read() function. The issue was resolved upstream and is listed as fixed in Linux kernel versions 5.15.12 and 5.16.
RHSA-2025:23445 released fixed RHEL 8.2 Advanced Update Support kernel packages addressing CVE-2025-39697.
RHSA-2025:22752 released fixed kernel packages for CVE-2025-39697 for RHEL 8.4 Advanced Mission Critical Update Support and Extended Update Support Long-Life Add-On systems.
RHSA-2025:22006 released kernel fixes for CVE-2025-39697 in RHEL 8.6 Advanced Mission Critical Update Support, Telecommunications Update Service, and SAP Solutions streams.
Red Hat released RHSA-2025:21917 for RHEL 8 kernel packages and RHSA-2025:21920 for RHEL 8 kernel-rt packages, both addressing CVE-2025-39697.
RHSA-2025:21118 released fixed RHEL 10 kernel packages addressing CVE-2025-39697.
Red Hat addressed the ALSA USB-audio out-of-bounds flaw through multiple RHSA advisories affecting RHEL 7, 8, and 9 extended-lifecycle, update-support, SAP, telecommunications, and mission-critical offerings.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
14 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.