CISA Mandates Urgent Patching for Three Actively Exploited Linux Kernel Flaws

CISA has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, ordering federal agencies to patch them by September 23, 2026. The flaws, ranging from medium to critical severity, are being actively exploited in the wild. While CISA has not disclosed details about the threat actors, Red Hat and other vendors have confirmed public exploits exist for two of the issues. The most critical flaw, CVE-2025-39964, has existed in the kernel for 14 years and allows for privilege escalation and container escape.
Key points
- CISA added CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682 to the KEV catalog, requiring federal patching by September 23, 2026.
- CVE-2025-39964 is a critical race condition in the AF_ALG cryptographic socket interface, discovered by STAR Labs without AI assistance, enabling privilege escalation and container escape.
- CVE-2026-53266 is an out-of-bounds write in the ebtables SNAT implementation, with a public exploit confirmed by Red Hat and a technical analysis published by researcher Kimmo Suominen.
- CVE-2025-39682 is a TLS receive-path logic flaw that mishandles zero-length records, with public exploits confirmed by Red Hat.
- CISA has not disclosed details regarding the nature of the threat actors or specific incidents, but has ordered forensic triage for all affected federal assets.
- None of the three flaws are currently flagged as being exploited by ransomware groups.
Background
This development follows a series of CISA alerts for actively exploited vulnerabilities in 2026, including Zimbra, SharePoint, and GitLab flaws. The Linux kernel has also seen a wave of AI-assisted privilege escalation disclosures, such as the DirtyAH6, TUNderflow, PPPoEject, and DiagSpill flaws disclosed in September 2026, and the Copy Fail vulnerability in April 2026. The current CISA alert highlights the ongoing risk of long-standing kernel flaws being actively exploited, even as new AI-driven discoveries emerge.
How outlets are covering it
BleepingComputer and SecurityWeek both report on the CISA KEV addition, with BleepingComputer emphasizing the 14-year age of CVE-2025-39964 and the STAR Labs discovery, while SecurityWeek provides detailed CVSS scores and technical descriptions of the flaws. The Hacker News focuses on a separate but related set of four Linux kernel flaws (DirtyAH6, TUNderflow, PPPoEject, DiagSpill) with public exploits, highlighting the AI-assisted nature of their discovery. Forkast.news discusses the Copy Fail vulnerability, emphasizing the deterministic nature of kernel crypto exploits and their impact on trust architecture. The outlets differ in their focus: BleepingComputer and SecurityWeek center on the CISA-mandated patching, while The Hacker News and Forkast.news highlight the broader trend of AI-assisted and deterministic kernel exploits.
Why it matters
The active exploitation of these Linux kernel flaws poses a significant risk to federal agencies and any organization running unpatched kernels. The critical nature of CVE-2025-39964, which enables privilege escalation and container escape, could lead to widespread compromise if not patched. The public availability of exploits for two of the three flaws increases the urgency for organizations to apply updates and conduct forensic triage to detect prior exploitation. The CISA mandate for federal agencies sets a precedent for the urgency of patching, and the lack of ransomware exploitation does not diminish the risk of other malicious actors.
What to watch
Federal agencies must apply available security updates and mitigations for the three flaws by September 23, 2026, and conduct forensic triage on all affected assets. Organizations outside the federal sector should also prioritize patching, especially given the public availability of exploits for CVE-2025-39682 and CVE-2026-53266. Researchers and security teams should monitor for signs of exploitation, particularly for the critical CVE-2025-39964, and consider disabling unprivileged user namespaces and unused kernel features as interim mitigations. The broader trend of AI-assisted kernel exploit discovery suggests that more such vulnerabilities may emerge, requiring ongoing vigilance and rapid patching.
- CISA alerts of active exploitation of three Linux kernel flaws BleepingComputer
- Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root The Hacker News
- Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities SecurityWeek
- 732 Bytes to Root: Copy Fail Turns the Kernel’s Crypto Subsystem Against Itself forkast.news
- CISA Warns of Linux Kernel Vulnerabilities Actively Exploited in Attacks CyberSecurityNews
Want the full story? Read the original reporting
Read on BleepingComputer