RHSA-2025:13135HighCVSS 7.8

Red Hat Security Advisory: kernel security update

Published
August 6, 2025
Last Modified
August 4, 2026

🔗 CVE IDs covered (21)

📋 Description

CVE-2021-47527 — kernel: serial: core: fix transmit-buffer reset and memleak CVE-2022-48669 — kernel: powerpc/pseries: Fix potential memleak in papr_get_attr() CVE-2022-49395 — kernel: um: Fix out-of-bounds read in LDT setup CVE-2022-49788 — kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() CVE-2023-52451 — kernel: powerpc: Fix access beyond end of drmem array CVE-2023-52764 — kernel: media: gspca: cpia1: shift-out-of-bounds in set_flicker CVE-2023-52877 — kernel: usb: typec: tcpm: Fix NULL pointer dereference in tcpm_pd_svdm() CVE-2024-26659 — kernel: xhci: handle isoc Babble and Buffer Overrun events properly CVE-2024-26934 — kernel: USB: core: Fix deadlock in usb_deauthorize_interface() CVE-2024-26964 — kernel: usb: xhci: Add error handling in xhci_map_urb_for_dma CVE-2024-27059 — kernel: USB: usb-storage: Prevent divide-by-0 error in isd200_ata_command CVE-2024-36945 — kernel: net/smc: fix neighbour and rtable leak in smc_ib_find_route() CVE-2024-43888 — kernel: mm: list_lru: fix UAF for memory cgroup CVE-2024-57980 — kernel: media: uvcvideo: Fix double free in error path CVE-2024-58002 — kernel: media: uvcvideo: Remove dangling pointers CVE-2025-21727 — kernel: padata: fix UAF in padata_reorder CVE-2025-21928 — kernel: HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove() CVE-2025-21991 — kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes CVE-2025-37890 — kernel: net_sched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc CVE-2025-37958 — kernel: mm/huge_memory: fix dereferencing invalid pmd migration entry CVE-2025-38052 — kernel: net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done

🎯 Affected products200

  • Red Hat CodeReady Linux Builder EUS (v.9.4)
  • Red Hat Enterprise Linux AppStream EUS (v.9.4)
  • Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • Red Hat Enterprise Linux Real Time EUS (v.9.4)
  • Red Hat Enterprise Linux Real Time for NFV EUS (v.9.4)
  • bpftool-0:7.3.0-427.81.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-0:7.3.0-427.81.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-0:7.3.0-427.81.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-0:7.3.0-427.81.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.81.1.el9_4.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.81.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.81.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.81.1.el9_4.ppc64le as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.81.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.81.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.81.1.el9_4.s390x as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.81.1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.81.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.81.1.el9_4.x86_64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.81.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.81.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.81.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.81.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.4)
  • kernel-0:5.14.0-427.81.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • kernel-0:5.14.0-427.81.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • kernel-0:5.14.0-427.81.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • kernel-0:5.14.0-427.81.1.el9_4.src as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • kernel-0:5.14.0-427.81.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • kernel-64k-0:5.14.0-427.81.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • kernel-64k-core-0:5.14.0-427.81.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • +170 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: No mitigation is currently available for this vulnerability. Make sure to perform the updates as they become available. Workaround: There is no known mitigation to this problem. Red Hat recommends updating to the latest kernel version to fix the problem. Workaround: To mitigate this issue, prevent module uvcvideo from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: In order to mitigate this issue it is possible to prevent the affected code from being loaded by blacklisting the kernel "USB Video Class module" (uvcvideo) module . For instructions relating to how to blacklist a kernel module refer to: https://access.redhat.com/solutions/41278uvcvideoz Workaround: To mitigate this issue, prevent module sch_hfsc from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation of this issue requires restricting access to the ability to create, modify, or destroy network namespaces. By default, this ability is restricted to privileged users. However, that restriction is only applicable to the host system itself and not to containerized applications. Administrators of container hosts should ensure that only trusted accounts can run containers.

🔗 References (24)