RHSA-2025:21091MediumCVSS 7.8

Red Hat Security Advisory: kernel security update

Published
November 12, 2025
Last Modified
June 29, 2026

🔗 CVE IDs covered (23)

📋 Description

CVE-2022-48701 — kernel: ALSA: usb-audio: ALSA USB Audio Out-of-Bounds Bug CVE-2022-50356 — kernel: net: sched: sfb: fix null pointer access issue when sfb_init() fails CVE-2022-50367 — kernel: fs: fix UAF/GPF bug in nilfs_mdt_destroy CVE-2022-50386 — kernel: Bluetooth: L2CAP: Fix user-after-free CVE-2022-50406 — kernel: iomap: iomap: fix memory corruption when recording errors during writeback CVE-2022-50408 — kernel: wifi: brcmfmac: fix use-after-free bug in brcmf_netdev_start_xmit() CVE-2023-53178 — kernel: mm: fix zswap writeback race condition CVE-2023-53185 — kernel: wifi: ath9k: don't allow to overwrite ENDPOINT0 attributes CVE-2023-53213 — kernel: wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies() CVE-2023-53226 — kernel: wifi: mwifiex: Fix OOB and integer underflow when rx packets CVE-2023-53232 — kernel: mt76: mt7921: fix kernel panic by accessing unallocated eeprom.data CVE-2023-53257 — kernel: wifi: mac80211: check S1G action frame size CVE-2023-53305 — kernel: Bluetooth: L2CAP: Fix use-after-free CVE-2023-53331 — kernel: pstore/ram: Check start of empty przs during init CVE-2023-53354 — kernel: skbuff: skb_segment, Call zero copy functions before using skbuff frags CVE-2023-53386 — kernel: Bluetooth: Fix potential use-after-free when clear keys CVE-2023-53401 — kernel: mm: kmem: fix a NULL pointer dereference in obj_stock_flush_required() CVE-2023-53494 — kernel: crypto: xts - Handle EBUSY correctly CVE-2025-38550 — kernel: ipv6: mcast: Delay put pmc->idev in mld_del_delrec() CVE-2025-38718 — kernel: sctp: linearize cloned gso packets in sctp_rcv CVE-2025-39697 — kernel: NFS: Fix a race when updating an existing write CVE-2025-39702 — kernel: ipv6: sr: Fix MAC comparison to be constant-time CVE-2025-39730 — kernel: NFS: Fix filehandle bounds checking in nfs_fh_to_dentry()

🔗 References (26)