In the Linux kernel, the following vulnerability has been resolved: crypto: algif_hash - fix double free in hash_accept If accept(2) is called on… (CVE-2025-38079)
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_hash - fix double free in hash_accept If accept(2) is called on socket type algif_hash with MSG_MORE flag set and crypto_ahash_import fails, sk2 is freed. However, it is also freed in af_alg_release, leading to slab-use-after-free error.
AI Analysis
Technical Summary
Red Hat Product Security issued an advisory for kernel security updates in Red Hat Enterprise Linux 9 to fix two vulnerabilities: CVE-2025-38079, a double free flaw in the crypto algif_hash hash_accept function, and CVE-2025-38292, an invalid memory access in the ath12k WiFi driver. These vulnerabilities could potentially lead to memory corruption issues. The advisory rates the security impact as moderate and provides updated kernel packages to address these issues. The update requires a system reboot for the fixes to be applied.
Potential Impact
The vulnerabilities involve memory management errors in the kernel's cryptographic and WiFi subsystems, which could lead to system instability or potential exploitation of memory corruption bugs. However, no known exploits are reported in the wild. The impact is rated moderate by Red Hat, indicating a significant but not critical risk to affected systems.
Mitigation Recommendations
Red Hat has released updated kernel packages that fix these vulnerabilities. Users should apply the available kernel updates for Red Hat Enterprise Linux 9 as described in the Red Hat advisory (RHSA-2025:13602) and reboot their systems to activate the patches. This is the official and recommended remediation.
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_hash - fix double free in hash_accept If accept(2) is called on… (CVE-2025-38079)
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_hash - fix double free in hash_accept If accept(2) is called on socket type algif_hash with MSG_MORE flag set and crypto_ahash_import fails, sk2 is freed. However, it is also freed in af_alg_release, leading to slab-use-after-free error.
CVSS v3.1
Score 7.8high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Red Hat Product Security issued an advisory for kernel security updates in Red Hat Enterprise Linux 9 to fix two vulnerabilities: CVE-2025-38079, a double free flaw in the crypto algif_hash hash_accept function, and CVE-2025-38292, an invalid memory access in the ath12k WiFi driver. These vulnerabilities could potentially lead to memory corruption issues. The advisory rates the security impact as moderate and provides updated kernel packages to address these issues. The update requires a system reboot for the fixes to be applied.
Potential Impact
The vulnerabilities involve memory management errors in the kernel's cryptographic and WiFi subsystems, which could lead to system instability or potential exploitation of memory corruption bugs. However, no known exploits are reported in the wild. The impact is rated moderate by Red Hat, indicating a significant but not critical risk to affected systems.
Mitigation Recommendations
Red Hat has released updated kernel packages that fix these vulnerabilities. Users should apply the available kernel updates for Red Hat Enterprise Linux 9 as described in the Red Hat advisory (RHSA-2025:13602) and reboot their systems to activate the patches. This is the official and recommended remediation.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:13602
- Cve Count
- 2
- Additional Cves
- ["CVE-2025-38292"]
- Cvss Version
- null
Threat ID: 6a3caf124853345fc153d7cf
Added to database: 06/25/2026, 04:31:14 UTC
Last enriched: 06/25/2026, 04:47:03 UTC
Last updated: 08/26/2026, 16:39:13 UTC
Views: 70
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.