- CISA added three Linux kernel flaws (CVE‑2025‑39682, CVE‑2026‑53266, CVE‑2025‑39964) to KEV catalog
- Crimson Hat confirmed energetic exploitation; businesses given uncommon three‑day patch deadline expiring Sept 21, 2026
- Bugs allow DoS, privilege escalation, or information corruption; patches accessible, restricted mitigations for 2 flaws
The US Cybersecurity and Infrastructure Safety Company (CISA) has added three Linux flaws to its Identified Exploited Vulnerabilities (KEV) catalog, signaling abuse within the wild and giving authorities businesses a deadline to patch or cease utilizing the flawed product solely.
The three bugs in query are tracked as CVE-2025-39682 (severity rating 9.8/10 – crucial), CVE-2026-53266 (severity rating 8.8/10 – excessive), and CVE-2025-39964 (severity rating 7.8/10 – excessive). All three have already been patched within the Linux kernel. CVE-2025-39682 was mounted in secure releases 6.1.149, 6.6.103, 6.12.44 and 6.16.4, whereas CVE-2025-39964 was mounted in 5.10.245, 5.15.194, 6.1.154, 6.6.108, 6.12.49 and 6.16.9. CVE-2026-53266 has been mounted upstream and backported to supported secure/distribution kernel branches, together with 5.10.259, 6.1.176 and 6.12.94.
The primary subject is an improper examine for uncommon or distinctive circumstances vulnerability within the TLS obtain patch which may enable unauthenticated menace actors to launch reminiscence disclosure or denial-of-service (DoS) assaults. The second (CVE-2026-53266) is an out-of-bounds write vulnerability within the ebtables Supply Community Deal with Translation (SNAT) Deal with Decision Protocol (ARP) rewrite patch which permits native attackers to escalate privileges or mount DoS assaults.
Newest Movies FromTechRadar
The final one (CVE-2025-39964) is a race situation flaw that permits concurrent writes to the identical AF_ALG socket, which permits native malicious actors to crash the system or corrupt cryptographic operation outcomes, resulting in information integrity points and doable DoS states.
Assaults within the wild
Crimson Hat acknowledged that each one three are being abused in real-life assaults. “This CVE is excessive danger and there are recognized public exploits leveraging this vulnerability. Deal with this vulnerability with excessive precedence,” it stated in all three advisories.
Nevertheless, there aren’t any particulars as to who’s presently utilizing these exploits, in opposition to whom, and to what trigger. There are presently no separate stories of cyberattacks referencing any of the abovementioned vulnerabilities.
Nevertheless, CISA nonetheless reacted. All three flaws have been added on September 18, 2026, and all three have a small three-day deadline for patching that expires on September 21. Normally, CISA would grant Federal Civilian Govt Department (FCEB) businesses a three-week deadline to patch up, with simply exceptionally harmful flaws getting a shorter window. That being stated, these flaws are seemingly extraordinarily harmful.
In principle…
In a hypothetical state of affairs, a menace actor may goal a Linux system utilizing kernel TLS (kTLS) by sending a specially-crafted TLS document that triggers CVE-2025-39682 and inflicting both a crash, and even arbitrary code execution. Attackers that have already got a low privilege foothold on the goal endpoint may use CVE_2025-39964 to escalate privileges, whereas on programs utilizing the affected bridge/netfilter configuration, CVE-2026-53266 might be used for privilege escalation, as properly.
Based on the Crimson Hat advisory, there’s a likelihood that CVE-2025-39682 is remotely triggerable, however solely when the system is utilizing the affected kTLS obtain path. The opposite two flaws are solely native vulnerabilities.
Apart from fixes, two out of the three flaws even have doable mitigations. For the improper examine one, customers ought to forestall module tls from being loaded. For the out-of-bounds write one, customers are suggested to disable ARP {hardware} handle rewriting in ebtables SNAT guidelines, or take away ebtables SNAT guidelines that function on ARP site visitors on bridge interfaces. The ultimate vulnerability, presently doesn’t have a working mitigation, and the one approach to keep safe is to use the supplied patches.
Linux kernel vulnerabilities are typically thought of severe, however the severity nonetheless relies on the flaw and the way the affected kernel is deployed. Earlier this 12 months, safety researchers disclosed 4 native privilege escalation flaws, known as DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121), and DiagSpill (CVE-2026-74469).
Through The Hacker Information
The most effective antivirus for all budgets
Observe TechRadar on Google Information and add us as a most popular supply to get our professional information, opinions, and opinion in your feeds.
