Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:13589

Опубликовано: 08 сент. 2025
Источник: rocky
Оценка: Moderate

Описание

Moderate: kernel security update

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: padata: fix UAF in padata_reorder (CVE-2025-21727)

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: padata: fix UAF in padata_reorder (CVE-2025-21727)

  • kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: padata: fix UAF in padata_reorder (CVE-2025-21727)

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: padata: fix UAF in padata_reorder (CVE-2025-21727)

  • kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)

  • kernel: can: peak_usb: fix use after free bugs (CVE-2021-47670)

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: padata: fix UAF in padata_reorder (CVE-2025-21727)

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: padata: fix UAF in padata_reorder (CVE-2025-21727)

  • kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: padata: fix UAF in padata_reorder (CVE-2025-21727)

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: padata: fix UAF in padata_reorder (CVE-2025-21727)

  • kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)

  • kernel: can: peak_usb: fix use after free bugs (CVE-2021-47670)

  • kernel: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race (CVE-2025-38085)

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: padata: fix UAF in padata_reorder (CVE-2025-21727)

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: padata: fix UAF in padata_reorder (CVE-2025-21727)

  • kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: padata: fix UAF in padata_reorder (CVE-2025-21727)

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: padata: fix UAF in padata_reorder (CVE-2025-21727)

  • kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)

  • kernel: can: peak_usb: fix use after free bugs (CVE-2021-47670)

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: padata: fix UAF in padata_reorder (CVE-2025-21727)

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: padata: fix UAF in padata_reorder (CVE-2025-21727)

  • kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: padata: fix UAF in padata_reorder (CVE-2025-21727)

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

The kernel packages contain the Linux kernel, the core of any Linux operating system.

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: padata: fix UAF in padata_reorder (CVE-2025-21727)

  • kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)

  • kernel: can: peak_usb: fix use after free bugs (CVE-2021-47670)

  • kernel: mm/hugetlb: fix huge_pmd_unshare() vs GUP-fast race (CVE-2025-38085)

  • kernel: wifi: rtw88: fix the 'para' buffer size to avoid reading out of bounds (CVE-2025-38159)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
bpftoolx86_64553.69.1.el8_10bpftool-4.18.0-553.69.1.el8_10.x86_64.rpm
kernelx86_64553.69.1.el8_10kernel-4.18.0-553.69.1.el8_10.x86_64.rpm
kernel-abi-stablelistsnoarch553.69.1.el8_10kernel-abi-stablelists-4.18.0-553.69.1.el8_10.noarch.rpm
kernel-corex86_64553.69.1.el8_10kernel-core-4.18.0-553.69.1.el8_10.x86_64.rpm
kernel-cross-headersx86_64553.69.1.el8_10kernel-cross-headers-4.18.0-553.69.1.el8_10.x86_64.rpm
kernel-debugx86_64553.69.1.el8_10kernel-debug-4.18.0-553.69.1.el8_10.x86_64.rpm
kernel-debug-corex86_64553.69.1.el8_10kernel-debug-core-4.18.0-553.69.1.el8_10.x86_64.rpm
kernel-debug-develx86_64553.69.1.el8_10kernel-debug-devel-4.18.0-553.69.1.el8_10.x86_64.rpm
kernel-debuginfo-common-x86_64x86_64553.69.1.el8_10kernel-debuginfo-common-x86_64-4.18.0-553.69.1.el8_10.x86_64.rpm
kernel-debug-modulesx86_64553.69.1.el8_10kernel-debug-modules-4.18.0-553.69.1.el8_10.x86_64.rpm

Показывать по

Связанные уязвимости

oracle-oval
около 2 месяцев назад

ELSA-2025-13589: kernel security update (MODERATE)

CVSS3: 7.8
ubuntu
6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: fix use after free bugs After calling peak_usb_netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the can_frame cf which aliases skb memory is accessed after the peak_usb_netif_rx_ni(). Reordering the lines solves the issue.

CVSS3: 7
redhat
6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: fix use after free bugs After calling peak_usb_netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the can_frame cf which aliases skb memory is accessed after the peak_usb_netif_rx_ni(). Reordering the lines solves the issue.

CVSS3: 7.8
nvd
6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: can: peak_usb: fix use after free bugs After calling peak_usb_netif_rx_ni(skb), dereferencing skb is unsafe. Especially, the can_frame cf which aliases skb memory is accessed after the peak_usb_netif_rx_ni(). Reordering the lines solves the issue.

CVSS3: 7.8
debian
6 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: c ...