Red Hat Security Advisory: kernel security update
🔗 CVE IDs covered (8)
📋 Description
CVE-2025-38141 — kernel: Linux kernel: Use-after-free in device mapper due to race condition in zone reporting CVE-2025-38349 — kernel: Linux kernel use-after-free in eventpoll CVE-2025-38731 — kernel: drm/xe: Fix vm_bind_ioctl double free bug CVE-2025-40248 — kernel: Linux kernel: vsock vulnerability may lead to memory corruption CVE-2025-40258 — kernel: mptcp: fix race condition in mptcp_schedule_work() CVE-2025-40294 — kernel: Linux kernel: Out-of-bounds write in Bluetooth MGMT can lead to information disclosure and denial of service CVE-2025-68301 — kernel: net: atlantic: fix fragment overflow handling in RX path CVE-2025-68305 — kernel: Bluetooth: hci_sock: Prevent race in socket write iter and sock bind
🎯 Affected products200
- Red Hat Enterprise Linux AppStream (v. 9)
- Red Hat Enterprise Linux BaseOS (v. 9)
- Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
- Red Hat Enterprise Linux Real Time (v. 9)
- Red Hat Enterprise Linux Real Time for NFV (v. 9)
- kernel-0:5.14.0-611.26.1.el9_7.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-0:5.14.0-611.26.1.el9_7.ppc64le as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-0:5.14.0-611.26.1.el9_7.s390x as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-0:5.14.0-611.26.1.el9_7.src as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-0:5.14.0-611.26.1.el9_7.x86_64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-64k-0:5.14.0-611.26.1.el9_7.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-64k-core-0:5.14.0-611.26.1.el9_7.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-64k-debug-0:5.14.0-611.26.1.el9_7.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-64k-debug-core-0:5.14.0-611.26.1.el9_7.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-64k-debug-debuginfo-0:5.14.0-611.26.1.el9_7.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- kernel-64k-debug-debuginfo-0:5.14.0-611.26.1.el9_7.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-64k-debug-debuginfo-0:5.14.0-611.26.1.el9_7.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
- kernel-64k-debug-debuginfo-0:5.14.0-611.26.1.el9_7.aarch64 as a component of Red Hat Enterprise Linux Real Time (v. 9)
- kernel-64k-debug-devel-0:5.14.0-611.26.1.el9_7.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- kernel-64k-debug-devel-matched-0:5.14.0-611.26.1.el9_7.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- kernel-64k-debug-modules-0:5.14.0-611.26.1.el9_7.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-64k-debug-modules-core-0:5.14.0-611.26.1.el9_7.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-64k-debug-modules-extra-0:5.14.0-611.26.1.el9_7.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-64k-debuginfo-0:5.14.0-611.26.1.el9_7.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- kernel-64k-debuginfo-0:5.14.0-611.26.1.el9_7.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- kernel-64k-debuginfo-0:5.14.0-611.26.1.el9_7.aarch64 as a component of Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)
- kernel-64k-debuginfo-0:5.14.0-611.26.1.el9_7.aarch64 as a component of Red Hat Enterprise Linux Real Time (v. 9)
- kernel-64k-devel-0:5.14.0-611.26.1.el9_7.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- kernel-64k-devel-matched-0:5.14.0-611.26.1.el9_7.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 9)
- kernel-64k-modules-0:5.14.0-611.26.1.el9_7.aarch64 as a component of Red Hat Enterprise Linux BaseOS (v. 9)
- +170 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Workaround: If enabled, you may disable MPTCP support. For more information please read https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/8/html/configuring_and_managing_networking/getting-started-with-multipath-tcp_configuring-and-managing-networking#preparing-rhel-to-enable-mptcp-support_getting-started-with-multipath-tcp Workaround: To mitigate this issue, the `bluetooth` kernel module can be prevented from loading. Create a file `/etc/modprobe.d/disable-bluetooth.conf` with the content `blacklist bluetooth`. Then, regenerate the initramfs using `dracut -f -v` and reboot the system for the changes to take effect. This mitigation will disable all Bluetooth functionality on the system. Workaround: To mitigate this issue, prevent the atlantic module from being loaded. See https://access.redhat.com/solutions/41278 for instructions.
🔗 References (11)
- selfhttps://access.redhat.com/errata/RHSA-2026:1143
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2376052
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2381870
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2393488
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2418872
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2418876
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2419891
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2422836
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2422840
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_1143.json