Red Hat Security Advisory: kernel security update
🔗 CVE IDs covered (11)
📋 Description
CVE-2024-24857 — kernel: net/bluetooth: race condition in conn_info_{min,max}_age_set() CVE-2024-26733 — kernel: arp: Prevent overflow in arp_req_get(). CVE-2024-26851 — kernel: netfilter: nf_conntrack_h323: Add protection for bmp length out of range CVE-2024-26940 — kernel: drm/vmwgfx: Create debugfs ttm_resource_manager entry only if needed CVE-2024-35854 — kernel: mlxsw: spectrum_acl_tcam: Fix possible use-after-free during rehash CVE-2024-36901 — kernel: ipv6: prevent NULL dereference in ip6_output() CVE-2024-36920 — kernel: scsi: mpi3mr: Avoid memcpy field-spanning write WARNING CVE-2024-36927 — kernel: ipv4: Fix uninit-value access in __ip_make_skb() CVE-2024-42084 — kernel: ftruncate: pass a signed offset CVE-2024-42265 — kernel: protect the fetch of ->fd[fd] in do_dup2() from mispredictions CVE-2025-21785 — kernel: arm64: cacheinfo: Avoid out-of-bounds write to cacheinfo array
🔗 References (13)
- selfhttps://access.redhat.com/errata/RHSA-2025:3215
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2266247
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2273247
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2275750
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278218
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281253
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2284500
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2284515
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2284634
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300533
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2348630
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_3215.json