RHSA-2025:13061: Important: kernel security update
Important: kernel security update
Other sources
The kernel packages contain the Linux kernel, the core of any Linux operating system.Security Fix(es): kernel: cifs: potential buffer overflow in handling symlinks (CVE-2022-49058) kernel: media: uvcvideo: Remove dangling pointers (CVE-2024-58002) kernel: padata: fix UAF in padatareorder (CVE-2025-21727) kernel: media: uvcvideo: Fix double free in error path (CVE-2024-57980) kernel: HID: intel-ish-hid: Fix use-after-free issue in ishtphidremove() (CVE-2025-21928) kernel: wifi: iwlwifi: limit printed string from FW file (CVE-2025-21905) kernel: net: atm: fix use after free in lecsend() (CVE-2025-22004) kernel: ext4: fix off-by-one error in dosplit (CVE-2025-23150) kernel: ext4: ignore xattrs past end (CVE-2025-37738) kernel: misc/vmwvmci: fix an infoleak in vmcihostdoreceivedatagram() (CVE-2022-49788) kernel: net/tipc: fix slab-use-after-free Read in tipcaeadencryptdone (CVE-2025-38052) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What security vulnerabilities are addressed in RHSA-2025:13061?
RHSA-2025:13061 addresses potential buffer overflow in handling symlinks (CVE-2022-49058) and issues related to dangling pointers in uvcvideo (CVE-2024-58002).
What is the severity of RHSA-2025:13061?
The severity of RHSA-2025:13061 is classified as important due to its potential impact on system security.
How do I fix RHSA-2025:13061?
To fix RHSA-2025:13061, you should update your kernel and related packages to version 4.18.0-477.104.1.el8_8.
What systems are affected by RHSA-2025:13061?
RHSA-2025:13061 affects various versions of Red Hat Enterprise Linux, including both x86_64 and Power LE architectures.
Is there a workaround for RHSA-2025:13061?
There is no specific workaround for RHSA-2025:13061; updating the affected packages is recommended.