RHSA-2025:22752MediumCVSS 7.8

Red Hat Security Advisory: kernel security update

Published
December 4, 2025
Last Modified
June 29, 2026

🔗 CVE IDs covered (41)

📋 Description

CVE-2022-48701 — kernel: ALSA: usb-audio: ALSA USB Audio Out-of-Bounds Bug CVE-2022-49969 — kernel: drm/amd/display: clear optc underflow before turn off odm clock CVE-2022-49985 — kernel: bpf: Don't use tnum_range on array range checking for poke descriptors CVE-2022-50050 — kernel: ASoC: SOF: Intel: hda: Fix potential buffer overflow by snprintf() CVE-2022-50070 — kernel: mptcp: do not queue data on closed subflows CVE-2022-50087 — kernel: firmware: arm_scpi: Ensure scpi_info is not assigned if the probe fails CVE-2022-50211 — kernel: md-raid10: fix KASAN warning CVE-2022-50228 — kernel: KVM: SVM: Don't BUG if userspace injects an interrupt with GIF=0 CVE-2022-50229 — kernel: ALSA: bcd2000: Fix a UAF bug on the error path of probing CVE-2022-50356 — kernel: net: sched: sfb: fix null pointer access issue when sfb_init() fails CVE-2022-50367 — kernel: fs: fix UAF/GPF bug in nilfs_mdt_destroy CVE-2022-50386 — kernel: Bluetooth: L2CAP: Fix user-after-free CVE-2022-50403 — kernel: ext4: fix undefined behavior in bit shift for ext4_check_flag_values CVE-2022-50408 — kernel: wifi: brcmfmac: fix use-after-free bug in brcmf_netdev_start_xmit() CVE-2022-50410 — kernel: NFSD: Protect against send buffer overflow in NFSv2 READ CVE-2023-53125 — kernel: net: usb: smsc75xx: Limit packet length to skb->len CVE-2023-53178 — kernel: mm: fix zswap writeback race condition CVE-2023-53185 — kernel: wifi: ath9k: don't allow to overwrite ENDPOINT0 attributes CVE-2023-53213 — kernel: wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies() CVE-2023-53305 — kernel: Bluetooth: L2CAP: Fix use-after-free CVE-2023-53354 — kernel: skbuff: skb_segment, Call zero copy functions before using skbuff frags CVE-2023-53373 — kernel: crypto: seqiv - Handle EBUSY correctly CVE-2023-53386 — kernel: Bluetooth: Fix potential use-after-free when clear keys CVE-2024-58240 — kernel: tls: separate no-async decryption request handling from async CVE-2025-22026 — kernel: nfsd: don't ignore the return code of svc_proc_register() CVE-2025-22058 — kernel: udp: Fix memory accounting leak. CVE-2025-37797 — kernel: net_sched: hfsc: Fix a UAF vulnerability in class handling CVE-2025-37914 — kernel: net_sched: ets: Fix double list add in class with netem as child qdisc CVE-2025-38200 — kernel: i40e: fix MMIO write access to an invalid page in i40e_clear_hw CVE-2025-38211 — kernel: RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction CVE-2025-38332 — kernel: scsi: lpfc: Use memcpy() for BIOS version CVE-2025-38449 — kernel: drm/gem: Acquire references on GEM handles for framebuffers CVE-2025-38461 — kernel: vsock: Fix transport_* TOCTOU CVE-2025-38477 — kernel: net/sched: sch_qfq: Fix race condition on qfq_aggregate CVE-2025-38498 — kernel: do_change_type(): refuse to operate on unmounted/not ours mounts CVE-2025-38527 — kernel: smb: client: fix use-after-free in cifs_oplock_break CVE-2025-38556 — kernel: HID: core: Harden s32ton() against conversion to 0 bits CVE-2025-39697 — kernel: NFS: Fix a race when updating an existing write CVE-2025-39730 — kernel: NFS: Fix filehandle bounds checking in nfs_fh_to_dentry() CVE-2025-39751 — kernel: Linux kernel ALSA hda/ca0132 buffer overflow CVE-2025-39864 — kernel: wifi: cfg80211: fix use-after-free in cmp_bss()

🔗 References (44)