Back to feed

CISA adds three exploited Linux kernel flaws to KEV catalog

1 min
CISA adds three exploited Linux kernel flaws to KEV catalog

This digest was compiled by AI from multiple sources — links to the originals are below.

The U.S. Cybersecurity and Infrastructure Security Agency added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog on Friday, citing active exploitation. Federal agencies must apply fixes by September 21, 2026 under Binding Operational Directive 26-04. Red Hat updated advisories for all three flaws as of September 19, 2026.

Key Facts

  • CVE-2025-39682 carries a CVSS score of 9.8 and affects the TLS receive path.
  • CVE-2026-53266 has a CVSS score of 8.8 and involves an out-of-bounds write in the ebtables SNAT ARP rewrite path.
  • CVE-2025-39964 has a CVSS score of 7.8 and is a race condition in AF_ALG socket handling.
  • Federal Civilian Executive Branch agencies must apply fixes by September 21, 2026 under BOD 26-04.
  • Security researcher Asim Manizada disclosed four local privilege escalation flaws, including CVE-2026-80844 (DirtyAH6) and CVE-2026-81000 (TUNderflow).

Vulnerability Details

CVE-2025-39682 is an improper check for unusual or exceptional conditions in the TLS receive path that could allow local authenticated users to trigger memory disclosure or denial-of-service. CVE-2026-53266 is an out-of-bounds write in the ebtables SNAT ARP rewrite path that could allow a local attacker to trigger unintended system behavior, denial-of-service, or local privilege escalation. CVE-2025-39964 is a race condition that could allow concurrent writes to the same AF_ALG socket, causing denial-of-service or data integrity issues.

Agency Response

CISA added the three flaws to its Known Exploited Vulnerabilities catalog on Friday, citing evidence of active exploitation. Red Hat updated advisories for all three flaws as of September 19, 2026 at 2 a.m. UTC to acknowledge active exploitation. Red Hat stated the vulnerabilities are high risk with known public exploits and should be addressed with high priority. Federal Civilian Executive Branch agencies are recommended to apply fixes by September 21, 2026 under Binding Operational Directive 26-04.

1 source

Time · lag behind first