Red Hat Security Advisory: kernel security update
🔗 CVE IDs covered (20)
📋 Description
CVE-2022-49969 — kernel: drm/amd/display: clear optc underflow before turn off odm clock CVE-2022-50087 — kernel: firmware: arm_scpi: Ensure scpi_info is not assigned if the probe fails CVE-2022-50228 — kernel: KVM: SVM: Don't BUG if userspace injects an interrupt with GIF=0 CVE-2022-50229 — kernel: ALSA: bcd2000: Fix a UAF bug on the error path of probing CVE-2023-53125 — kernel: net: usb: smsc75xx: Limit packet length to skb->len CVE-2024-58240 — kernel: tls: separate no-async decryption request handling from async CVE-2025-22026 — kernel: nfsd: don't ignore the return code of svc_proc_register() CVE-2025-37797 — kernel: net_sched: hfsc: Fix a UAF vulnerability in class handling CVE-2025-38085 — kernel: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race CVE-2025-38159 — kernel: wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds CVE-2025-38200 — kernel: i40e: fix MMIO write access to an invalid page in i40e_clear_hw CVE-2025-38211 — kernel: RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction CVE-2025-38332 — kernel: scsi: lpfc: Use memcpy() for BIOS version CVE-2025-38449 — kernel: drm/gem: Acquire references on GEM handles for framebuffers CVE-2025-38477 — kernel: net/sched: sch_qfq: Fix race condition on qfq_aggregate CVE-2025-38498 — kernel: do_change_type(): refuse to operate on unmounted/not ours mounts CVE-2025-38527 — kernel: smb: client: fix use-after-free in cifs_oplock_break CVE-2025-38556 — kernel: HID: core: Harden s32ton() against conversion to 0 bits CVE-2025-39730 — kernel: NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() CVE-2025-39751 — kernel: Linux kernel ALSA hda/ca0132 buffer overflow
🎯 Affected products26
- Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- bpftool-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- bpftool-debuginfo-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- kernel-0:4.18.0-193.173.1.el8_2.src as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- kernel-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- kernel-abi-whitelists-0:4.18.0-193.173.1.el8_2.noarch as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- kernel-core-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- kernel-debug-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- kernel-debug-core-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- kernel-debug-debuginfo-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- kernel-debug-devel-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- kernel-debug-modules-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- kernel-debug-modules-extra-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- kernel-debuginfo-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- kernel-debuginfo-common-x86_64-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- kernel-devel-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- kernel-doc-0:4.18.0-193.173.1.el8_2.noarch as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- kernel-modules-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- kernel-modules-extra-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- kernel-tools-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- kernel-tools-debuginfo-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- kernel-tools-libs-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- perf-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- perf-debuginfo-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- python3-perf-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
- python3-perf-debuginfo-0:4.18.0-193.173.1.el8_2.x86_64 as a component of Red Hat Enterprise Linux BaseOS AUS (v. 8.2)
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: To mitigate this issue, prevent module smsc75xx from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent module tls from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent module sch_hfsc from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent module rtw88 from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent InfiniBand modules from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. The names of the modules are: ib_addr, ib_cm, ib_core, ib_mad, ib_sa, ib_ucm, ib_umad, iw_cm. Workaround: To mitigate this issue, prevent module drm from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: To mitigate this issue, prevent module sch_qfq from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this issue, prevent module nfs from being loaded. Please see https://access.redhat.com/solutions/41278 for how to blacklist a kernel module to prevent it from loading automatically.
🔗 References (23)
- selfhttps://access.redhat.com/errata/RHSA-2025:21667
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2360224
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2363672
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2363686
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2373460
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2373529
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2373539
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2373635
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2375304
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2376064
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2376392
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2376406
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2379246
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2383519
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2383922
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2384422
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2388928
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2389456
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2391431
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2393731
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2394624
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_21667.json