Particle.news

CISA Orders Rapid Patch of Three Actively Exploited Linux Kernel Flaws

The directive forces federal agencies to remediate by September 21 and requires forensic triage after vendors confirmed in‑the‑wild exploitation.

Overview

  • The Cybersecurity and Infrastructure Security Agency added CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266 to its Known Exploited Vulnerabilities catalog and told federal agencies to apply fixes by September 21, 2026.
  • CVE-2025-39682 is a critical TLS receive-path logic error that can let a local authenticated user cause memory disclosure or crash the system when kernel TLS processing mishandles zero-length records.
  • CVE-2025-39964 is a long-standing race condition in AF_ALG crypto sockets that can let concurrent writes corrupt cryptographic results or crash systems, and researchers have demonstrated privilege escalation and container escape scenarios.
  • CVE-2026-53266 is an out-of-bounds write in the ebtables SNAT ARP rewrite path that can corrupt shared memory, trigger denial-of-service, or lead to local privilege escalation under certain conditions.
  • Vendors such as Red Hat have published high-priority advisories and fixes, and operators are urged to patch immediately, inventory exposed or multi-tenant Linux hosts, and perform forensic hunts for signs of exploitation while triaging additional kernel LPE disclosures from researcher Asim Manizada.