CISA lists three exploited Linux kernel flaws, one a 14-year race
CISA added three exploited Linux kernel bugs to its KEV catalog, with a September 21, 2026 federal deadline, including a 14-year AF_ALG flaw used for local root and Docker escape.
The U.S. Cybersecurity and Infrastructure Security Agency added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2025-39682 (CVSS 9.8), a TLS/kTLS receive-path flaw involving zero-length records that can disclose memory or cause denial of service; CVE-2026-53266 (CVSS 8.8), an out-of-bounds write in the ebtables SNAT path reachable by a crafted ARP packet; and CVE-2025-39964 (CVSS 7.8), an AF_ALG socket race. Under BOD 22-01, federal civilian agencies were told to remediate by September 21, 2026—SecurityWeek called that a three-day window and GBHackers says the CVE-2025-39964 listing was dated September 18, 2026—while BleepingComputer said the deadline was same-day and required forensic triage. Security Affairs limits CVE-2025-39682 to authenticated local users; BleepingComputer says severities range from medium to critical, Red Hat reports public exploits for CVE-2025-39682 and CVE-2026-53266, and CISA has not named actors, described in-the-wild exploitation, or flagged ransomware use. CVE-2025-39964 dates to Linux 2.6.38 in 2011 (a researcher account says about 2011 and analysis on 6.12.44): STAR Labs’ Muhammad Alifa Ramdhan and Bing-Jhong Billy Jheng showed unprivileged local root and a Docker escape in Google’s kernelCTF for a $113,337 reward, say it was responsibly disclosed, and distinguish it from a later AF_ALG “Copy Fail” AEAD bug. Sources disagree on patched stable kernels—GBHackers lists 5.10.245, 5.15.194, 6.1.154, 6.6.108, 6.12.49, and 6.16.9, while Cyber Security News lists the next point releases (5.10.246 through 6.16.10) and says the fix adds exclusive write ownership.
- CISA added three exploited Linux kernel flaws to the KEV catalog: CVE-2025-39682 (CVSS 9.8), CVE-2026-53266 (CVSS 8.8), and CVE-2025-39964 (CVSS 7.8).
- Under BOD 22-01, federal civilian agencies were told to remediate by September 21, 2026; GBHackers dates the CVE-2025-39964 listing to September 18, 2026, and BleepingComputer says forensic triage is required.
- CVE-2025-39682 is a TLS/kTLS receive-path flaw involving zero-length records that can disclose memory or cause denial of service; Security Affairs limits it to authenticated local users, and Red Hat reports a public exploit.
- CVE-2026-53266 is an out-of-bounds write in the ebtables SNAT path reachable by a crafted ARP packet; Red Hat reports a public exploit. CISA has not named actors or flagged ransomware use.
- CVE-2025-39964 is an AF_ALG socket race present since Linux 2.6.38 in 2011 (a researcher write-up says about 2011 and analysis on kernel 6.12.44) that yields local root and a Docker escape.
Coverage timelineoldest first · each row is one article
- · 6d agoU.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
Security Affairs· 78
CISA added three actively exploited Linux kernel flaws (CVE-2025-39682, CVE-2025-39964, CVE-2026-53266) to its KEV catalog, federal patch deadline September 21, 2026.
- · 5d agoOrganizations Warned of 3 Exploited Linux Kernel Vulnerabilities
SecurityWeek· 75
CISA added three exploited Linux kernel flaws to its KEV catalog, ordering federal agencies to patch within three days.
- · 5d agoCISA alerts of active exploitation of three Linux kernel flaws
BleepingComputer· 88
Vulnerabilities in this storyAll →
- CVE-2025-396829.83%Improper Condition Check in Linux Kernel kTLS Receive Path Enables Local Info Leak/DoSpublished · Linux Kernel KEV