Important: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: net: gso: fix ownership in __udp_gso_segment (CVE-2025-21926) * kernel: vlan: enforce underlying device type (CVE-2025-21920) * kernel: xsk: fix an integer overflow in xp_create_and_assign_umem() (CVE-2025-21997) * kernel: net: fix geneve_opt length integer overflow (CVE-2025-22055) * kernel: ext4: fix OOB read when checking dotdot dir (CVE-2025-37785) * kernel: wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi (CVE-2025-37943) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: net: gso: fix ownership in __udp_gso_segment (CVE-2025-21926) * kernel: vlan: enforce underlying device type (CVE-2025-21920) * kernel: xsk: fix an integer overflow in xp_create_and_assign_umem() (CVE-2025-21997) * kernel: net: fix geneve_opt length integer overflow (CVE-2025-22055) * kernel: ext4: fix OOB read when checking dotdot dir (CVE-2025-37785) * kernel: wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi (CVE-2025-37943) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2025:8643
- https://access.redhat.com/security/cve/CVE-2025-21920
- https://access.redhat.com/security/cve/CVE-2025-21926
- https://access.redhat.com/security/cve/CVE-2025-21997
- https://access.redhat.com/security/cve/CVE-2025-22055
- https://access.redhat.com/security/cve/CVE-2025-37785
- https://access.redhat.com/security/cve/CVE-2025-37943
- https://bugzilla.redhat.com/2356587
- https://bugzilla.redhat.com/2356639
- https://bugzilla.redhat.com/2357143
- https://bugzilla.redhat.com/2360300
- https://bugzilla.redhat.com/2360921
- https://bugzilla.redhat.com/2367748
- https://errata.almalinux.org/9/ALSA-2025-8643.html