Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:10829 - Security Advisory
Issued:
2025-07-14
Updated:
2025-07-14

RHSA-2025:10829 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: kernel-rt security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for kernel-rt is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

The kernel-rt packages provide the Real Time Linux Kernel, which enables fine-tuning for systems with extremely high determinism requirements.

Security Fix(es):

  • kernel: um: Fix out-of-bounds read in LDT setup (CVE-2022-49395)
  • kernel: dm ioctl: prevent potential spectre v1 gadget (CVE-2022-49122)
  • kernel: ipv6: mcast: extend RCU protection in igmp6_send() (CVE-2025-21759)
  • kernel: Squashfs: fix handling and sanity checking of xattr_ids count (CVE-2023-52933)
  • kernel: net: atm: fix use after free in lec_send() (CVE-2025-22004)
  • kernel: ext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all() (CVE-2025-22121)
  • kernel: ibmvnic: Use kernel helpers for hex dumps (CVE-2025-22104)
  • kernel: ext4: ignore xattrs past end (CVE-2025-37738)
  • kernel: udf: Fix a slab-out-of-bounds write bug in udf_find_entry() (CVE-2022-49846)
  • kernel: net: atlantic: fix aq_vec index out of range error (CVE-2022-50066)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

The system must be rebooted for this update to take effect.

Affected Products

  • Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0 x86_64

Fixes

  • BZ - 2347899 - CVE-2022-49395 kernel: um: Fix out-of-bounds read in LDT setup
  • BZ - 2348154 - CVE-2022-49122 kernel: dm ioctl: prevent potential spectre v1 gadget
  • BZ - 2348596 - CVE-2025-21759 kernel: ipv6: mcast: extend RCU protection in igmp6_send()
  • BZ - 2355476 - CVE-2023-52933 kernel: Squashfs: fix handling and sanity checking of xattr_ids count
  • BZ - 2357142 - CVE-2025-22004 kernel: net: atm: fix use after free in lec_send()
  • BZ - 2360199 - CVE-2025-22121 kernel: ext4: fix out-of-bound read in ext4_xattr_inode_dec_ref_all()
  • BZ - 2360265 - CVE-2025-22104 kernel: ibmvnic: Use kernel helpers for hex dumps
  • BZ - 2363305 - CVE-2025-37738 kernel: ext4: ignore xattrs past end
  • BZ - 2363432 - CVE-2022-49846 kernel: udf: Fix a slab-out-of-bounds write bug in udf_find_entry()
  • BZ - 2373683 - CVE-2022-50066 kernel: net: atlantic: fix aq_vec index out of range error

CVEs

  • CVE-2022-49122
  • CVE-2022-49395
  • CVE-2022-49846
  • CVE-2022-50066
  • CVE-2023-52933
  • CVE-2025-21759
  • CVE-2025-22004
  • CVE-2025-22104
  • CVE-2025-22121
  • CVE-2025-37738

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.0

SRPM
kernel-rt-5.14.0-70.138.1.rt21.210.el9_0.src.rpm SHA-256: 56e93d4813023672e316e243865a42aac8314f51401f76e7833023dd56284884
x86_64
kernel-rt-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: c352547c13d6c2ddbbf5131b0aa8d3bbeee501cead5bee05b508f1766a0ecfb9
kernel-rt-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: c352547c13d6c2ddbbf5131b0aa8d3bbeee501cead5bee05b508f1766a0ecfb9
kernel-rt-core-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: e296496cfa906eb813f3065a4b8726a3ec91dff5f91403a1da51c986b7ad1316
kernel-rt-core-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: e296496cfa906eb813f3065a4b8726a3ec91dff5f91403a1da51c986b7ad1316
kernel-rt-debug-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: 2fc4bd13513b687d5086de192fdeed5a1af82a400f9f31ab0a21453274894717
kernel-rt-debug-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: 2fc4bd13513b687d5086de192fdeed5a1af82a400f9f31ab0a21453274894717
kernel-rt-debug-core-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: 9f55288b297f8f3917d554d3fe69051c508aa2bf48fb2fab4455db841cd0d243
kernel-rt-debug-core-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: 9f55288b297f8f3917d554d3fe69051c508aa2bf48fb2fab4455db841cd0d243
kernel-rt-debug-debuginfo-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: 77b4fd6b78f65eb5f2e00f4689b75ea0a260fa11c0d38111a700adae6d0792f7
kernel-rt-debug-debuginfo-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: 77b4fd6b78f65eb5f2e00f4689b75ea0a260fa11c0d38111a700adae6d0792f7
kernel-rt-debug-devel-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: 5d070d692c088b283c6b0bf1ae050217c76295e81e39186228ddb19ccbc7d9f7
kernel-rt-debug-devel-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: 5d070d692c088b283c6b0bf1ae050217c76295e81e39186228ddb19ccbc7d9f7
kernel-rt-debug-kvm-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: 74a9f5ba47f9d5a5a73c0f91be48d66d91877844d8143679a2f7d2e02ef066e8
kernel-rt-debug-modules-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: 8ae1e3c62350277474e6e159ca8995b37d4ff98edad837f3d5dace5c501fb274
kernel-rt-debug-modules-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: 8ae1e3c62350277474e6e159ca8995b37d4ff98edad837f3d5dace5c501fb274
kernel-rt-debug-modules-extra-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: 161c8326e88ca70c59e28dfa96e2119f877e6f8da9ac1f77ad5a5630d9904b1e
kernel-rt-debug-modules-extra-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: 161c8326e88ca70c59e28dfa96e2119f877e6f8da9ac1f77ad5a5630d9904b1e
kernel-rt-debuginfo-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: 511d4b1d908bf718e38f56d1f5d3ee650f510dc788397c51b46352fe041669b3
kernel-rt-debuginfo-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: 511d4b1d908bf718e38f56d1f5d3ee650f510dc788397c51b46352fe041669b3
kernel-rt-debuginfo-common-x86_64-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: ff991af5e87f9761c947c0e0d5d648b27ed89f972204ceb422e1a3d893d7c4ec
kernel-rt-debuginfo-common-x86_64-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: ff991af5e87f9761c947c0e0d5d648b27ed89f972204ceb422e1a3d893d7c4ec
kernel-rt-devel-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: cab60e13438e06babdfaecc202c4dab9fa37313d9d632008611d521c0df134d7
kernel-rt-devel-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: cab60e13438e06babdfaecc202c4dab9fa37313d9d632008611d521c0df134d7
kernel-rt-kvm-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: 5b63b68b1d1a956538f88242ce0d147893a2391713c9ad9bfe5240ccf67a1993
kernel-rt-modules-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: 85cae78a8ff334587c426ed4b0e1e8e19f54236b4793df001865a4bf3206ac43
kernel-rt-modules-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: 85cae78a8ff334587c426ed4b0e1e8e19f54236b4793df001865a4bf3206ac43
kernel-rt-modules-extra-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: b285ac4b064882777257411710cd0765fefaa41e161ae8b77530e5f983f3909f
kernel-rt-modules-extra-5.14.0-70.138.1.rt21.210.el9_0.x86_64.rpm SHA-256: b285ac4b064882777257411710cd0765fefaa41e161ae8b77530e5f983f3909f

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility