Red Hat Security Advisory: kernel security update
🔗 CVE IDs covered (13)
📋 Description
CVE-2023-52623 — kernel: SUNRPC: Fix a suspicious RCU usage warning CVE-2023-52662 — kernel: drm/vmwgfx: fix a memleak in vmw_gmrid_man_get_node CVE-2024-26638 — kernel: nbd: always initialize struct msghdr completely CVE-2024-26669 — kernel: net/sched: flower: Fix chain template offload CVE-2024-26939 — kernel: drm/i915/vma: Fix UAF on destroy against retire race CVE-2024-35838 — kernel: wifi: mac80211: fix potential sta-link leak CVE-2024-35847 — kernel: irqchip/gic-v3-its: Prevent double free on error CVE-2024-36917 — kernel: block: fix overflow in blk_ioctl_discard() CVE-2024-41042 — kernel: netfilter: nf_tables: prefer nft_chain_validate CVE-2024-56615 — kernel: bpf: fix OOB devmap writes when deleting elements CVE-2024-58099 — kernel: vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frame CVE-2025-21764 — kernel: ndisc: use RCU protection in ndisc_alloc_skb() CVE-2025-38234 — kernel: sched/rt: Fix race in push_rt_task
🎯 Affected products200
- Red Hat CodeReady Linux Builder EUS (v.9.4)
- Red Hat Enterprise Linux AppStream EUS (v.9.4)
- Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- Red Hat Enterprise Linux Real Time EUS (v.9.4)
- Red Hat Enterprise Linux Real Time for NFV EUS (v.9.4)
- bpftool-0:7.3.0-427.74.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- bpftool-0:7.3.0-427.74.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- bpftool-0:7.3.0-427.74.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- bpftool-0:7.3.0-427.74.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.74.1.el9_4.aarch64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.74.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.74.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.74.1.el9_4.ppc64le as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.74.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux AppStream EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.74.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.74.1.el9_4.s390x as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.74.1.el9_4.s390x as a component of Red Hat Enterprise Linux AppStream EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.74.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.74.1.el9_4.x86_64 as a component of Red Hat CodeReady Linux Builder EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.74.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux AppStream EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.74.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.74.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux Real Time EUS (v.9.4)
- bpftool-debuginfo-0:7.3.0-427.74.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux Real Time for NFV EUS (v.9.4)
- kernel-0:5.14.0-427.74.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- kernel-0:5.14.0-427.74.1.el9_4.ppc64le as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- kernel-0:5.14.0-427.74.1.el9_4.s390x as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- kernel-0:5.14.0-427.74.1.el9_4.src as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- kernel-0:5.14.0-427.74.1.el9_4.x86_64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- kernel-64k-0:5.14.0-427.74.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- kernel-64k-core-0:5.14.0-427.74.1.el9_4.aarch64 as a component of Red Hat Enterprise Linux BaseOS EUS (v.9.4)
- +170 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2025:9584
- externalhttps://access.redhat.com/security/updates/classification/#moderate
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2270103
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2271686
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2272795
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2278220
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281157
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281268
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2281360
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2284519
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2300412
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2334493
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2348575
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2362882
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_9584.json