Important: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too (CVE-2025-37823) * kernel: i40e: fix MMIO write access to an invalid page in i40e_clear_hw (CVE-2025-38200) * kernel: RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction (CVE-2025-38211) * kernel: net/sched: Always pass notifications when child class becomes empty (CVE-2025-38350) * kernel: tipc: Fix use-after-free in tipc_conn_close() (CVE-2025-38464) * kernel: vsock: Fix transport_* TOCTOU (CVE-2025-38461) * kernel: xfrm: interface: fix use-after-free after changing collect_md xfrm interface (CVE-2025-38500) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: net_sched: hfsc: Fix a potential UAF in hfsc_dequeue() too (CVE-2025-37823) * kernel: i40e: fix MMIO write access to an invalid page in i40e_clear_hw (CVE-2025-38200) * kernel: RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction (CVE-2025-38211) * kernel: net/sched: Always pass notifications when child class becomes empty (CVE-2025-38350) * kernel: tipc: Fix use-after-free in tipc_conn_close() (CVE-2025-38464) * kernel: vsock: Fix transport_* TOCTOU (CVE-2025-38461) * kernel: xfrm: interface: fix use-after-free after changing collect_md xfrm interface (CVE-2025-38500) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2025:15011
- https://bugzilla.redhat.com/2365024
- https://bugzilla.redhat.com/2376392
- https://bugzilla.redhat.com/2376406
- https://bugzilla.redhat.com/2382054
- https://bugzilla.redhat.com/2383509
- https://bugzilla.redhat.com/2383513
- https://bugzilla.redhat.com/2387866
- https://errata.almalinux.org/9/ALSA-2025-15011.html
- https://www.redhat.com/security/data/cve/CVE-2025-37823.html
- https://www.redhat.com/security/data/cve/CVE-2025-38200.html
- https://www.redhat.com/security/data/cve/CVE-2025-38211.html
- https://www.redhat.com/security/data/cve/CVE-2025-38350.html
- https://www.redhat.com/security/data/cve/CVE-2025-38461.html
- https://www.redhat.com/security/data/cve/CVE-2025-38464.html
- https://www.redhat.com/security/data/cve/CVE-2025-38500.html
- https://www.redhat.com/security/data/cve/CVE-2025-38684.html