RHSA-2025:2270MediumCVSS 7.8

Red Hat Security Advisory: kernel security update

Published
March 5, 2025
Last Modified
August 4, 2026

🔗 CVE IDs covered (21)

📋 Description

CVE-2019-25162 — kernel: use after free in i2c CVE-2021-47432 — kernel: lib/generic-radix-tree.c: Don't overflow in peek() CVE-2023-52648 — kernel: drm/vmwgfx: Unmap the surface before resetting it on a plane state CVE-2023-52683 — kernel: ACPI: LPIT: Avoid u32 multiplication overflow CVE-2023-52791 — kernel: i2c: core: Run atomic i2c xfer when !preemptible CVE-2024-26740 — kernel: net/sched: act_mirred: use the backlog for mirred ingress CVE-2024-26759 — kernel: mm/swap: fix race when skipping swapcache CVE-2024-26843 — kernel: efi: runtime: Fix potential overflow of soft-reserved region size CVE-2024-26846 — kernel: nvme-fc: do not wait in vain when unloading module CVE-2024-26894 — kernel: ACPI: processor_idle: Fix memory leak in acpi_processor_power_exit() CVE-2024-27395 — kernel: net: openvswitch: Fix Use-After-Free in ovs_ct_exit CVE-2024-35947 — kernel: dyndbg: fix old BUG_ON in >control parser CVE-2024-35959 — kernel: net/mlx5e: Fix mlx5e_priv_init() cleanup flow CVE-2024-36905 — kernel: tcp: defer shutdown(SEND_SHUTDOWN) for TCP_SYN_RECV sockets CVE-2024-39276 — kernel: ext4: fix mb_cache_entry's e_refcnt leak in ext4_xattr_block_cache_find() CVE-2024-42292 — kernel: kobject_uevent: Fix OOB access within zap_modalias_env() CVE-2024-43889 — kernel: padata: Fix possible divide-by-0 panic in padata_mt_helper() CVE-2024-44935 — kernel: sctp: Fix null-ptr-deref in reuseport_add_sock(). CVE-2024-44990 — kernel: bonding: fix null pointer deref in bond_ipsec_offload_ok CVE-2024-49949 — kernel: net: avoid potential underflow in qdisc_pkt_len_init() with UFO CVE-2024-50099 — kernel: arm64: probes: Remove broken LDR (literal) uprobe support

🎯 Affected products200

  • Red Hat CodeReady Linux Builder EUS (v.9.4)
  • Red Hat Enterprise Linux AppStream EUS (v.9.4)
  • Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • Red Hat Enterprise Linux Real Time EUS (v.9.4)
  • Red Hat Enterprise Linux Real Time for NFV EUS (v.9.4)
  • bpftool-0:7.3.0-427.57.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-0:7.3.0-427.57.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-0:7.3.0-427.57.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-0:7.3.0-427.57.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.57.1.el9_4.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.57.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.57.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.57.1.el9_4.ppc64le as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.57.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.57.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.57.1.el9_4.s390x as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.57.1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.57.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.57.1.el9_4.x86_64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.57.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.57.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.57.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.4)
  • bpftool-debuginfo-0:7.3.0-427.57.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.4)
  • kernel-0:5.14.0-427.57.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • kernel-0:5.14.0-427.57.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • kernel-0:5.14.0-427.57.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • kernel-0:5.14.0-427.57.1.el9_4.src as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • kernel-0:5.14.0-427.57.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • kernel-64k-0:5.14.0-427.57.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • kernel-64k-core-0:5.14.0-427.57.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
  • +170 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

🔗 References (23)