Security News

Cybersecurity news aggregator

🐧
MEDIUM Updates Web Discovery

redhat.com

  • What: Red Hat released a security update for the Linux kernel in Red Hat Enterprise Linux 9 to address two vulnerabilities.
  • Impact: The update fixes a nested key length validation issue in openvswitch and a use-after-free vulnerability in irqchip/gic-v2m.
  • CVE: CVE-2025-37789, CVE-2025-37819
Read Full Article →

Red Hat Product Errata RHSA-2026:2212 - Security Advisory Issued: 2026-02-09 Updated: 2026-02-09 RHSA-2026:2212 - Security Advisory Synopsis Moderate: kernel security update Type/Severity Security Advisory: Moderate Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for kernel is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): kernel: net: openvswitch: fix nested key length validation in the set() action (CVE-2025-37789) kernel: Linux kernel: irqchip/gic-v2m use-after-free vulnerability (CVE-2025-37819) kernel: RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device" problem (CVE-2025-38022) kernel: Linux kernel: RDMA/rxe use-after-free vulnerability leading to potential arbitrary code execution (CVE-2025-38024) kernel: Linux kernel: Memory corruption in Squashfs due to incorrect block size calculation (CVE-2025-38415) kernel: vsock/vmci: Clear the vmci transport packet properly when initializing it (CVE-2025-38403) kernel: Linux kernel: Denial of Service in ATM CLIP module via infinite recursion (CVE-2025-38459) kernel: Linux kernel: Data corruption and system instability due to improper io_uring/net buffer handling (CVE-2025-38730) kernel: Linux kernel: Denial of Service via out-of-bounds read in USB configuration parsing (CVE-2025-39760) kernel: net: use dst_dev_rcu() in sk_setup_caps() (CVE-2025-40170) kernel: ipv6: use RCU in ip6_xmit() (CVE-2025-40135) kernel: Bluetooth: ISO: Fix possible UAF on iso_conn_free (CVE-2025-40141) kernel: ipv6: use RCU in ip6_output() (CVE-2025-40158) kernel: Linux kernel: Use-after-free in proc_readdir_de() can lead to privilege escalation or denial of service. (CVE-2025-40271) kernel: Linux kernel ALSA USB audio driver: Buffer overflow leading to information disclosure and denial of service (CVE-2025-40269) kernel: Bluetooth: hci_sync: fix race in hci_cmd_sync_dequeue_once (CVE-2025-40318) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 The system must be rebooted for this update to take effect. Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat CodeReady Linux Builder for x86_64 9 x86_64 Red Hat CodeReady Linux Builder for Power, little endian 9 ppc64le Red Hat CodeReady Linux Builder for ARM 64 9 aarch64 Red Hat CodeReady Linux Builder for IBM z Systems 9 s390x Fixes BZ - 2363315 - CVE-2025-37789 kernel: net: openvswitch: fix nested key length validation in the set() action BZ - 2365032 - CVE-2025-37819 kernel: Linux kernel: irqchip/gic-v2m use-after-free vulnerability BZ - 2373326 - CVE-2025-38022 kernel: RDMA/core: Fix "KASAN: slab-use-after-free Read in ib_register_device" problem BZ - 2373354 - CVE-2025-38024 kernel: Linux kernel: RDMA/rxe use-after-free vulnerability leading to potential arbitrary code execution BZ - 2383404 - CVE-2025-38415 kernel: Linux kernel: Memory corruption in Squashfs due to incorrect block size calculation BZ - 2383421 - CVE-2025-38403 kernel: vsock/vmci: Clear the vmci transport packet properly when initializing it BZ - 2383487 - CVE-2025-38459 kernel: Linux kernel: Denial of Service in ATM CLIP module via infinite recursion BZ - 2393191 - CVE-2025-38730 kernel: Linux kernel: Data corruption and system instability due to improper io_uring/net buffer handling BZ - 2394601 - CVE-2025-39760 kernel: Linux kernel: Denial of Service via out-of-bounds read in USB configuration parsing BZ - 2414506 - CVE-2025-40170 kernel: net: use dst_dev_rcu() in sk_setup_caps() BZ - 2414521 - CVE-2025-40135 kernel: ipv6: use RCU in ip6_xmit() BZ - 2414522 - CVE-2025-40141 kernel: Bluetooth: ISO: Fix possible UAF on iso_conn_free BZ - 2414523 - CVE-2025-40158 kernel: ipv6: use RCU in ip6_output() BZ - 2419837 - CVE-2025-40271 kernel: Linux kernel: Use-after-free in proc_readdir_de() can lead to privilege escalation or denial of service. BZ - 2419919 - CVE-2025-40269 kernel: Linux kernel ALSA USB audio driver: Buffer overflow leading to information disclosure and denial of service BZ - 2419920 - CVE-2025-40318 kernel: Bluetooth: hci_sync: fix race in hci_cmd_sync_dequeue_once CVEs CVE-2025-37789 CVE-2025-37819 CVE-2025-38022 CVE-

Share this article