Moderate: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction (CVE-2025-38211) * kernel: scsi: lpfc: Use memcpy() for BIOS version (CVE-2025-38332) * kernel: tipc: Fix use-after-free in tipc_conn_close() (CVE-2025-38464) * kernel: net/sched: sch_qfq: Fix race condition on qfq_aggregate (CVE-2025-38477) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction (CVE-2025-38211) * kernel: scsi: lpfc: Use memcpy() for BIOS version (CVE-2025-38332) * kernel: tipc: Fix use-after-free in tipc_conn_close() (CVE-2025-38464) * kernel: net/sched: sch_qfq: Fix race condition on qfq_aggregate (CVE-2025-38477) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2025:15008
- https://access.redhat.com/security/cve/CVE-2025-38211
- https://access.redhat.com/security/cve/CVE-2025-38332
- https://access.redhat.com/security/cve/CVE-2025-38464
- https://access.redhat.com/security/cve/CVE-2025-38477
- https://bugzilla.redhat.com/2376406
- https://bugzilla.redhat.com/2379246
- https://bugzilla.redhat.com/2383509
- https://bugzilla.redhat.com/2383922
- https://errata.almalinux.org/8/ALSA-2025-15008.html