RHSA-2025:16580: Important: kpatch-patch-4_18_0-372_118_1, kpatch-patch-4_18_0-372_131_1, kpatch-patch-4_18_0-372_137_1, and kpatch-patch-4_18_0-372_145_1 security update
Important: kpatch-patch-4180-3721181, kpatch-patch-4180-3721311, kpatch-patch-4180-3721371, and kpatch-patch-4180-3721451 security update
Other sources
This is a kernel live patch module which can be loaded by the kpatch command line utility to modify the code of a running kernel. This patch module is targeted for kernel-4.18.0-372.118.1.el86.Security Fix(es): kernel: netsched: hfsc: Fix a UAF vulnerability in class with netem as child qdisc (CVE-2025-37890) kernel: netsched: hfsc: Address reentrant enqueue adding class to eltree twice (CVE-2025-38001) kernel: schhfsc: Fix qlen accounting bug when using peek in hfscenqueue() (CVE-2025-38000) kernel: net/sched: Always pass notifications when child class becomes empty (CVE-2025-38350) kernel: i2c/designware: Fix an initialization issue (CVE-2025-38380) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_118_1-1-11.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_131_1-1-10.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_137_1-1-7.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_145_1-1-5.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_118_1-debuginfo-1-11.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_118_1-debugsource-1-11.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_131_1-debuginfo-1-10.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_131_1-debugsource-1-10.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_137_1-debuginfo-1-7.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_137_1-debugsource-1-7.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_145_1-debuginfo-1-5.el8_6 - Upgrade
Upgrade
redhat/kpatch-patchto a version that resolves this vulnerability.Fixed in 4_18_0-372_145_1-debugsource-1-5.el8_6 - Upgrade
Upgrade
kernel-4.18.0-372.118.1.el8_6to a version that resolves this vulnerability.Patch kpatch-patch-4_18_0-372_118_1 - Upgrade
Upgrade
kernel-4.18.0-372.118.1.el8_6to a version that resolves this vulnerability.Patch kpatch-patch-4_18_0-372_131_1 - Upgrade
Upgrade
kernel-4.18.0-372.118.1.el8_6to a version that resolves this vulnerability.Patch kpatch-patch-4_18_0-372_137_1 - Upgrade
Upgrade
kernel-4.18.0-372.118.1.el8_6to a version that resolves this vulnerability.Patch kpatch-patch-4_18_0-372_145_1 - Operational
Reboot the system after applying the kernel live patch updates so the update takes effect.
Event History
Frequently Asked Questions
What is the severity of RHSA-2025:16580?
The severity of RHSA-2025:16580 is classified as Important.
How do I fix RHSA-2025:16580?
To fix RHSA-2025:16580, you should update to the latest version of the kpatch-patch package as specified in the advisory.
Which software is affected by RHSA-2025:16580?
RHSA-2025:16580 affects various versions of Red Hat Enterprise Linux, including support for x86_64 and Power LE architectures.
What is kpatch in RHSA-2025:16580?
Kpatch is a kernel live patching utility that allows patches to be applied to a running kernel without rebooting.
Is a reboot required after applying the fix for RHSA-2025:16580?
No, the fix for RHSA-2025:16580 can be applied without requiring a reboot.