{"id":2041,"date":"2026-09-21T07:18:55","date_gmt":"2026-09-21T00:18:55","guid":{"rendered":"https:\/\/vncybers.vn\/cisa-canh-bao-ba-lo-hong-linux-kernel-dang-bi-khai-thac\/"},"modified":"2026-09-21T07:22:17","modified_gmt":"2026-09-21T00:22:17","slug":"cisa-warns-three-linux-kernel-flaws-exploited-in-the-wild","status":"publish","type":"post","link":"https:\/\/vncybers.vn\/en\/cisa-canh-bao-ba-lo-hong-linux-kernel-dang-bi-khai-thac\/","title":{"rendered":"CISA Warns Three Linux Kernel Vulnerabilities Are Being Actually Exploited"},"content":{"rendered":"<p>The US Cybersecurity and Infrastructure Security Agency (CISA) has placed three vulnerabilities in the Linux Kernel in the Known Exploited Vulnerabilities (KEV) category after confirming there is evidence of real-world exploitation. Errors related to the TLS receive path, ebtables, and the AF_ALG cryptographic interface, can lead to memory leaks, denial of service, data corruption, or local escalation of privilege.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/vncybers.vn\/wp-content\/uploads\/2026\/09\/linux-admin-inline.jpg\" alt=\"Linux administrator checking and updating a server\"\/><figcaption>Administrators need to prioritize kernel version inventory and vendor patch deployment. Photo: Unsplash\/Gabriel Heinzer<\/figcaption><\/figure>\n<h2>Three Linux Kernel vulnerabilities in the KEV category<\/h2>\n<p>CISA added all three vulnerabilities on September 18, 2026. Appearing in KEV means that this agency has evidence that the bug has been exploited in the wild; This is not just a risk assessment based on the CVSS score.<\/p>\n<ul>\n<li><strong>CVE-2025-39682<\/strong> is an error checking for an abnormal condition in the TLS receive path. A zero-length record can bypass expected record type processing, causing subsequent records to be processed with incorrect assumptions about zero-copy and queuing. Consequences may include memory exposure or denial of service.<\/li>\n<li><strong>CVE-2026-53266<\/strong> is an out-of-bounds write error in ebtables SNAT when rewriting the hardware address of an ARP packet. A local attacker could cause unexpected behavior, crash the system, or escalate privileges.<\/li>\n<li><strong>CVE-2025-39964<\/strong> is a contention condition when multiple processes simultaneously write to the same AF_ALG socket. Data can be interleaved, causing inconsistent internal state, causing denial of service, or compromising the integrity of cryptographic results.<\/li>\n<\/ul>\n<h2>The level of risk needs to be properly understood<\/h2>\n<p>The Hacker News leads the CVSS scores at 9.8; 8.8 and 7.8. However, the scope of impact and exploitability depends on the kernel configuration, distribution, enabled features, and permissions the attacker has. The following two flaws are described in terms of local attacks, so they are especially notable on shared servers, compromised workstations, or container environments with weak permission boundaries.<\/p>\n<p>CISA has not released campaign details, exploit code, or whether the three bugs are combined in the same attack chain. The KEV catalog also notes that it is unclear whether these vulnerabilities are related to ransomware campaigns.<\/p>\n<h2>CISA processing deadlines and requirements<\/h2>\n<p>CISA sets a processing deadline of September 21, 2026 for agencies of the US federal civil executive branch according to BOD 26-04. The guidance requires vendor-specific mitigation, performing appropriate forensic analysis, and discontinuing use of the product if there is no available remedy.<\/p>\n<p>While the directive is directly mandatory for US federal systems in scope, other organizations should consider KEV as a signal of priority in vulnerability management. Red Hat has also updated the alert to note the exploit status and recommend high priority action.<\/p>\n<h2>Which systems need to be checked first?<\/h2>\n<p>Operations teams should start with Internet-facing servers, sensitive data storage infrastructure, multi-user servers, container platforms, and devices running old or out of support kernels. Do not infer from the generic version name alone, as each vendor can backport the patch without changing to the latest kernel version number.<\/p>\n<p>It is necessary to compare the kernel package version with the bulletin of the distribution in use, and also check that the kernel is actually running after the update. Installing a package without restarting may cause the system to continue operating with vulnerable code.<\/p>\n<h2>Recommended Response Process<\/h2>\n<ol>\n<li>Make a list of Linux assets, running kernel version, distribution, system roles, and network exposure.<\/li>\n<li>Check CVEs against official vendor alerts instead of relying solely on scanners or version strings.<\/li>\n<li>Prioritize patching systems with many users, untrusted workloads, or previous signs of compromise; Test the update with important apps.<\/li>\n<li>Reboot into the patched kernel when required by the vendor, then verify the running version and service status.<\/li>\n<li>Review logs, processes, accounts, privilege changes, and unusual kernel crashes for signs of exploitation; Isolate assets if suspicious indicators are detected.<\/li>\n<\/ol>\n<h2>Minimize when updates cannot be made immediately<\/h2>\n<p>If patching is not possible, the organization should apply the vendor's specific instructions. The attack surface can be reduced by limiting local login permissions, tightening untrusted workloads, disabling unnecessary components when verified by the vendor as safe, increasing monitoring, and isolating critical systems. These measures do not replace patching.<\/p>\n<h2>Lessons for vulnerability management<\/h2>\n<p>Facts show that the CVSS score is not enough to determine processing order. Evidence of actual exploitation, exposure, required rights and asset value must be combined in the same prioritization process. With Linux, an accurate inventory and tracking of each distribution's backport mechanism is as important as vulnerability scanning.<\/p>\n<p>Organizations should include the KEV catalog in their patch management flow, clearly define processing deadlines, and save post-update verification evidence. This approach helps shorten the time between when a warning is announced and when the actual risk is eliminated.<\/p>\n<p style=\"text-align: right; margin-top: 40px;\"><em><strong>VNCyberS<\/strong> compiled from CISA and The Hacker News<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>C\u01a1 quan An ninh m\u1ea1ng v\u00e0 C\u01a1 s\u1edf h\u1ea1 t\u1ea7ng M\u1ef9 (CISA) \u0111\u00e3 \u0111\u01b0a ba l\u1ed7 h\u1ed5ng trong Linux Kernel v\u00e0o danh m\u1ee5c Known Exploited Vulnerabilities (KEV) sau khi x\u00e1c nh\u1eadn c\u00f3 b\u1eb1ng ch\u1ee9ng khai th\u00e1c th\u1ef1c t\u1ebf. C\u00e1c l\u1ed7i li\u00ean quan \u0111\u1ebfn \u0111\u01b0\u1eddng nh\u1eadn TLS, ebtables v\u00e0 giao di\u1ec7n m\u1eadt m\u00e3 AF_ALG, c\u00f3 th\u1ec3 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":2040,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[1],"tags":[37,850,852,851,849,269,575,853],"class_list":["post-2041","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tin-tuc","tag-cisa","tag-cve-2025-39682","tag-cve-2025-39964","tag-cve-2026-53266","tag-kev","tag-leo-thang-dac-quyen","tag-linux-kernel","tag-quan-ly-lo-hong"],"_links":{"self":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/2041","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/comments?post=2041"}],"version-history":[{"count":1,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/2041\/revisions"}],"predecessor-version":[{"id":2042,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/2041\/revisions\/2042"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media\/2040"}],"wp:attachment":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media?parent=2041"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/categories?post=2041"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/tags?post=2041"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}