Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
CISA added three exploited Linux kernel flaws to its KEV catalog, ordering federal agencies to patch within three days.
CISA expanded its Known Exploited Vulnerabilities catalog with three Linux kernel flaws and told federal agencies to patch within three days. CVE-2025-39682 (CVSS 9.8) is a critical flaw in TLS receive-path handling of zero-length records enabling DoS or memory disclosure; CVE-2025-39964 (CVSS 7.8) is an AF_ALG socket race condition causing crashes or corrupted cryptographic results; CVE-2026-53266 (CVSS 8.8) is an out-of-bounds write in the ebtables SNAT target triggered by a crafted ARP packet. CISA has not shared exploitation details.
75