RHSA-2025:21760MediumCVSS 7.8
Red Hat Security Advisory: kernel security update
🔗 CVE IDs covered (9)
📋 Description
CVE-2023-53494 — kernel: crypto: xts - Handle EBUSY correctly CVE-2025-38718 — kernel: sctp: linearize cloned gso packets in sctp_rcv CVE-2025-38729 — kernel: ALSA: usb-audio: Validate UAC3 power domain descriptors, too CVE-2025-39697 — kernel: NFS: Fix a race when updating an existing write CVE-2025-39702 — kernel: ipv6: sr: Fix MAC comparison to be constant-time CVE-2025-39757 — kernel: ALSA: usb-audio: Validate UAC3 cluster segment descriptors CVE-2025-39817 — kernel: efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare CVE-2025-39849 — kernel: wifi: cfg80211: sme: cap SSID length in __cfg80211_connect_result() CVE-2025-40300 — kernel: x86/vmscape: Add conditional IBPB mitigation
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2025:21760
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2393164
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2393166
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2393481
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2393533
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2394615
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2394627
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2395805
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2396928
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2400777
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_21760.json