www.securityweek.com 21 Sept 2026, 09:31 UTC

CISA Flags Three Exploited Linux Kernel Flaws for Urgent Fixes

CISA Flags Three Exploited Linux Kernel Flaws for Urgent Fixes

THE US Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalogue and instructed federal agencies to apply fixes within three days. However, CISA has not published details about how the flaws are being exploited, so the available information confirms their inclusion in the exploited-vulnerability catalogue but does not describe observed attacks.

CVE-2025-39682 is a critical flaw, rated CVSS 9.8, in the kernel’s TLS receive path. An issue involving zero-length records and zero-copy decryption could allow a local attacker to cause a denial-of-service condition or memory disclosure. CVE-2025-39964, rated 7.8, is a race condition affecting writes to the same AF_ALG socket. Concurrent writes can be interleaved, corrupting the socket’s internal state or cryptographic results and potentially crashing the system.

CVE-2026-53266, rated 8.8, is an out-of-bounds write in the bridge Netfilter ebtables SNAT target. A crafted packet containing an ARP payload could cause an ARP hardware address to be written into the wrong socket-buffer area, resulting in memory corruption and unauthorised modification outside the intended buffer. Organisations using affected Linux kernel builds should prioritise vendor-provided updates.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline