Moderate: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: ublk: make sure ubq->canceling is set when queue is frozen (CVE-2025-22068) * kernel: scsi: lpfc: Use memcpy() for BIOS version (CVE-2025-38332) * kernel: idpf: convert control queue mutex to a spinlock (CVE-2025-38392) * kernel: tcp: Correct signedness in skb remaining space calculation (CVE-2025-38463) * kernel: do_change_type(): refuse to operate on unmounted/not ours mounts (CVE-2025-38498) * kernel: xfrm: interface: fix use-after-free after changing collect_md xfrm interface (CVE-2025-38500) * kernel: ipv6: mcast: Delay put pmc->idev in mld_del_delrec() (CVE-2025-38550) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: ublk: make sure ubq->canceling is set when queue is frozen (CVE-2025-22068) * kernel: scsi: lpfc: Use memcpy() for BIOS version (CVE-2025-38332) * kernel: idpf: convert control queue mutex to a spinlock (CVE-2025-38392) * kernel: tcp: Correct signedness in skb remaining space calculation (CVE-2025-38463) * kernel: do_change_type(): refuse to operate on unmounted/not ours mounts (CVE-2025-38498) * kernel: xfrm: interface: fix use-after-free after changing collect_md xfrm interface (CVE-2025-38500) * kernel: ipv6: mcast: Delay put pmc->idev in mld_del_delrec() (CVE-2025-38550) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2025:15782
- https://access.redhat.com/security/cve/CVE-2025-22068
- https://access.redhat.com/security/cve/CVE-2025-38332
- https://access.redhat.com/security/cve/CVE-2025-38392
- https://access.redhat.com/security/cve/CVE-2025-38463
- https://access.redhat.com/security/cve/CVE-2025-38498
- https://access.redhat.com/security/cve/CVE-2025-38500
- https://access.redhat.com/security/cve/CVE-2025-38550
- https://bugzilla.redhat.com/2360225
- https://bugzilla.redhat.com/2379246
- https://bugzilla.redhat.com/2383407
- https://bugzilla.redhat.com/2383493
- https://bugzilla.redhat.com/2384422
- https://bugzilla.redhat.com/2387866
- https://bugzilla.redhat.com/2388941
- https://errata.almalinux.org/10/ALSA-2025-15782.html