Moderate: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() (CVE-2025-38724) * kernel: wifi: cfg80211: fix use-after-free in cmp_bss() (CVE-2025-39864) * kernel: e1000e: fix heap overflow in e1000_set_eeprom (CVE-2025-39898) * kernel: wifi: mt76: fix linked list corruption (CVE-2025-39918) * kernel: tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect() (CVE-2025-39955) * kernel: Bluetooth: MGMT: Fix possible UAFs (CVE-2025-39981) * kernel: iommu/vt-d: Disallow dirty tracking if incoherent page walk (CVE-2025-40058) * kernel: ice: ice_adapter: release xa entry on adapter allocation failure (CVE-2025-40185) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm() (CVE-2025-38724) * kernel: wifi: cfg80211: fix use-after-free in cmp_bss() (CVE-2025-39864) * kernel: e1000e: fix heap overflow in e1000_set_eeprom (CVE-2025-39898) * kernel: wifi: mt76: fix linked list corruption (CVE-2025-39918) * kernel: tcp: Clear tcp_sk(sk)->fastopen_rsk in tcp_disconnect() (CVE-2025-39955) * kernel: Bluetooth: MGMT: Fix possible UAFs (CVE-2025-39981) * kernel: iommu/vt-d: Disallow dirty tracking if incoherent page walk (CVE-2025-40058) * kernel: ice: ice_adapter: release xa entry on adapter allocation failure (CVE-2025-40185) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2025:22405
- https://access.redhat.com/security/cve/CVE-2025-38724
- https://access.redhat.com/security/cve/CVE-2025-39864
- https://access.redhat.com/security/cve/CVE-2025-39898
- https://access.redhat.com/security/cve/CVE-2025-39918
- https://access.redhat.com/security/cve/CVE-2025-39955
- https://access.redhat.com/security/cve/CVE-2025-39981
- https://access.redhat.com/security/cve/CVE-2025-40058
- https://access.redhat.com/security/cve/CVE-2025-40185
- https://bugzilla.redhat.com/2393172
- https://bugzilla.redhat.com/2396934
- https://bugzilla.redhat.com/2400598
- https://bugzilla.redhat.com/2400628
- https://bugzilla.redhat.com/2402699
- https://bugzilla.redhat.com/2404105
- https://bugzilla.redhat.com/2406776
- https://bugzilla.redhat.com/2414741
- https://errata.almalinux.org/9/ALSA-2025-22405.html