Important: kernel security update
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: eth: bnxt: fix truesize for mb-xdp-pass case (CVE-2025-21961) * kernel: Bluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd (CVE-2025-21969) * kernel: cifs: Fix integer overflow while processing acdirmax mount option (CVE-2025-21963) * kernel: wifi: cfg80211: cancel wiphy_work before freeing wiphy (CVE-2025-21979) * kernel: proc: fix UAF in proc_get_inode() (CVE-2025-21999) * kernel: md: fix mddev uaf while iterating all_mddevs list (CVE-2025-22126) * kernel: smb: client: fix UAF in decryption with multichannel (CVE-2025-37750) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The kernel packages contain the Linux kernel, the core of any Linux operating system. Security Fix(es): * kernel: eth: bnxt: fix truesize for mb-xdp-pass case (CVE-2025-21961) * kernel: Bluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd (CVE-2025-21969) * kernel: cifs: Fix integer overflow while processing acdirmax mount option (CVE-2025-21963) * kernel: wifi: cfg80211: cancel wiphy_work before freeing wiphy (CVE-2025-21979) * kernel: proc: fix UAF in proc_get_inode() (CVE-2025-21999) * kernel: md: fix mddev uaf while iterating all_mddevs list (CVE-2025-22126) * kernel: smb: client: fix UAF in decryption with multichannel (CVE-2025-37750) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
05 / REFERENCES
Further evidence
- https://access.redhat.com/errata/RHSA-2025:9080
- https://access.redhat.com/security/cve/CVE-2025-21961
- https://access.redhat.com/security/cve/CVE-2025-21963
- https://access.redhat.com/security/cve/CVE-2025-21969
- https://access.redhat.com/security/cve/CVE-2025-21979
- https://access.redhat.com/security/cve/CVE-2025-21999
- https://access.redhat.com/security/cve/CVE-2025-22126
- https://access.redhat.com/security/cve/CVE-2025-37750
- https://bugzilla.redhat.com/2356584
- https://bugzilla.redhat.com/2356633
- https://bugzilla.redhat.com/2356642
- https://bugzilla.redhat.com/2356652
- https://bugzilla.redhat.com/2357134
- https://bugzilla.redhat.com/2360236
- https://bugzilla.redhat.com/2363341
- https://errata.almalinux.org/9/ALSA-2025-9080.html