CISA Warns Three Linux Kernel Vulnerabilities Are Being Actually Exploited

The US Cybersecurity and Infrastructure Security Agency (CISA) has placed three vulnerabilities in the Linux Kernel in the Known Exploited Vulnerabilities (KEV) category after confirming there is evidence of real-world exploitation. Errors related to the TLS receive path, ebtables, and the AF_ALG cryptographic interface, can lead to memory leaks, denial of service, data corruption, or local escalation of privilege.

Linux administrator checking and updating a server
Administrators need to prioritize kernel version inventory and vendor patch deployment. Photo: Unsplash/Gabriel Heinzer

Three Linux Kernel vulnerabilities in the KEV category

CISA added all three vulnerabilities on September 18, 2026. Appearing in KEV means that this agency has evidence that the bug has been exploited in the wild; This is not just a risk assessment based on the CVSS score.

  • CVE-2025-39682 is an error checking for an abnormal condition in the TLS receive path. A zero-length record can bypass expected record type processing, causing subsequent records to be processed with incorrect assumptions about zero-copy and queuing. Consequences may include memory exposure or denial of service.
  • CVE-2026-53266 is an out-of-bounds write error in ebtables SNAT when rewriting the hardware address of an ARP packet. A local attacker could cause unexpected behavior, crash the system, or escalate privileges.
  • CVE-2025-39964 is a contention condition when multiple processes simultaneously write to the same AF_ALG socket. Data can be interleaved, causing inconsistent internal state, causing denial of service, or compromising the integrity of cryptographic results.

The level of risk needs to be properly understood

The Hacker News leads the CVSS scores at 9.8; 8.8 and 7.8. However, the scope of impact and exploitability depends on the kernel configuration, distribution, enabled features, and permissions the attacker has. The following two flaws are described in terms of local attacks, so they are especially notable on shared servers, compromised workstations, or container environments with weak permission boundaries.

CISA has not released campaign details, exploit code, or whether the three bugs are combined in the same attack chain. The KEV catalog also notes that it is unclear whether these vulnerabilities are related to ransomware campaigns.

CISA processing deadlines and requirements

CISA sets a processing deadline of September 21, 2026 for agencies of the US federal civil executive branch according to BOD 26-04. The guidance requires vendor-specific mitigation, performing appropriate forensic analysis, and discontinuing use of the product if there is no available remedy.

While the directive is directly mandatory for US federal systems in scope, other organizations should consider KEV as a signal of priority in vulnerability management. Red Hat has also updated the alert to note the exploit status and recommend high priority action.

Which systems need to be checked first?

Operations teams should start with Internet-facing servers, sensitive data storage infrastructure, multi-user servers, container platforms, and devices running old or out of support kernels. Do not infer from the generic version name alone, as each vendor can backport the patch without changing to the latest kernel version number.

It is necessary to compare the kernel package version with the bulletin of the distribution in use, and also check that the kernel is actually running after the update. Installing a package without restarting may cause the system to continue operating with vulnerable code.

Recommended Response Process

  1. Make a list of Linux assets, running kernel version, distribution, system roles, and network exposure.
  2. Check CVEs against official vendor alerts instead of relying solely on scanners or version strings.
  3. Prioritize patching systems with many users, untrusted workloads, or previous signs of compromise; Test the update with important apps.
  4. Reboot into the patched kernel when required by the vendor, then verify the running version and service status.
  5. Review logs, processes, accounts, privilege changes, and unusual kernel crashes for signs of exploitation; Isolate assets if suspicious indicators are detected.

Minimize when updates cannot be made immediately

If patching is not possible, the organization should apply the vendor's specific instructions. The attack surface can be reduced by limiting local login permissions, tightening untrusted workloads, disabling unnecessary components when verified by the vendor as safe, increasing monitoring, and isolating critical systems. These measures do not replace patching.

Lessons for vulnerability management

Facts show that the CVSS score is not enough to determine processing order. Evidence of actual exploitation, exposure, required rights and asset value must be combined in the same prioritization process. With Linux, an accurate inventory and tracking of each distribution's backport mechanism is as important as vulnerability scanning.

Organizations should include the KEV catalog in their patch management flow, clearly define processing deadlines, and save post-update verification evidence. This approach helps shorten the time between when a warning is announced and when the actual risk is eliminated.

VNCyberS compiled from CISA and The Hacker News

Contact Us

Email: [email protected]
Phone: +84 903260277