Moderate: kernel-rt security update
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: cifs: potential buffer overflow in handling symlinks (CVE-2022-49058) * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002) * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980) * kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes (CVE-2025-21991) * kernel: net: atm: fix use after free in lec_send() (CVE-2025-22004) * kernel: ext4: fix off-by-one error in do_split (CVE-2025-23150) * kernel: ext4: ignore xattrs past end (CVE-2025-37738) * kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() (CVE-2022-49788) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements. Security Fix(es): * kernel: cifs: potential buffer overflow in handling symlinks (CVE-2022-49058) * kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002) * kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980) * kernel: x86/microcode/AMD: Fix out-of-bounds on systems with CPU-less NUMA nodes (CVE-2025-21991) * kernel: net: atm: fix use after free in lec_send() (CVE-2025-22004) * kernel: ext4: fix off-by-one error in do_split (CVE-2025-23150) * kernel: ext4: ignore xattrs past end (CVE-2025-37738) * kernel: misc/vmw_vmci: fix an infoleak in vmci_host_do_receive_datagram() (CVE-2022-49788) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2025:11299
- https://access.redhat.com/security/cve/CVE-2022-49058
- https://access.redhat.com/security/cve/CVE-2022-49788
- https://access.redhat.com/security/cve/CVE-2024-57980
- https://access.redhat.com/security/cve/CVE-2024-58002
- https://access.redhat.com/security/cve/CVE-2025-21991
- https://access.redhat.com/security/cve/CVE-2025-22004
- https://access.redhat.com/security/cve/CVE-2025-23150
- https://access.redhat.com/security/cve/CVE-2025-37738
- https://bugzilla.redhat.com/2348254
- https://bugzilla.redhat.com/2348513
- https://bugzilla.redhat.com/2348599
- https://bugzilla.redhat.com/2356917
- https://bugzilla.redhat.com/2357142
- https://bugzilla.redhat.com/2363268
- https://bugzilla.redhat.com/2363305
- https://bugzilla.redhat.com/2363378
- https://errata.almalinux.org/8/ALSA-2025-11299.html