RHSA-2025:23445HighCVSS 7.8

Red Hat Security Advisory: kernel security update

Published
December 17, 2025
Last Modified
June 29, 2026

🔗 CVE IDs covered (31)

📋 Description

CVE-2022-48701 — kernel: ALSA: usb-audio: ALSA USB Audio Out-of-Bounds Bug CVE-2022-50356 — kernel: net: sched: sfb: fix null pointer access issue when sfb_init() fails CVE-2022-50367 — kernel: fs: fix UAF/GPF bug in nilfs_mdt_destroy CVE-2022-50386 — kernel: Bluetooth: L2CAP: Fix user-after-free CVE-2022-50403 — kernel: ext4: fix undefined behavior in bit shift for ext4_check_flag_values CVE-2022-50406 — kernel: iomap: iomap: fix memory corruption when recording errors during writeback CVE-2022-50408 — kernel: wifi: brcmfmac: fix use-after-free bug in brcmf_netdev_start_xmit() CVE-2022-50410 — kernel: NFSD: Protect against send buffer overflow in NFSv2 READ CVE-2023-53178 — kernel: mm: fix zswap writeback race condition CVE-2023-53213 — kernel: wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies() CVE-2023-53226 — kernel: wifi: mwifiex: Fix OOB and integer underflow when rx packets CVE-2023-53297 — kernel: Bluetooth: L2CAP: fix "bad unlock balance" in l2cap_disconnect_rsp CVE-2023-53305 — kernel: Bluetooth: L2CAP: Fix use-after-free CVE-2023-53354 — kernel: skbuff: skb_segment, Call zero copy functions before using skbuff frags CVE-2023-53365 — kernel: ip6mr: Fix skb_under_panic in ip6mr_cache_report() CVE-2023-53373 — kernel: crypto: seqiv - Handle EBUSY correctly CVE-2023-53393 — kernel: RDMA/mlx5: Fix mlx5_ib_get_hw_stats when used for device CVE-2023-53680 — kernel: NFSD: Avoid calling OPDESC() with ops->opnum == OP_ILLEGAL CVE-2024-46679 — kernel: ethtool: check device is present when getting link settings CVE-2025-38718 — kernel: sctp: linearize cloned gso packets in sctp_rcv CVE-2025-38724 — kernel: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() CVE-2025-38729 — kernel: ALSA: usb-audio: Validate UAC3 power domain descriptors, too CVE-2025-39697 — kernel: NFS: Fix a race when updating an existing write CVE-2025-39757 — kernel: ALSA: usb-audio: Validate UAC3 cluster segment descriptors CVE-2025-39817 — kernel: efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare CVE-2025-39825 — kernel: smb: client: fix race with concurrent opens in rename(2) CVE-2025-39841 — kernel: scsi: lpfc: Fix buffer free/clear order in deferred receive path CVE-2025-39864 — kernel: wifi: cfg80211: fix use-after-free in cmp_bss() CVE-2025-39883 — kernel: mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory CVE-2025-39955 — kernel: tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect() CVE-2025-40186 — kernel: Linux kernel: Privilege escalation or Denial of Service via TCP Fast Open vulnerability

🔗 References (34)