The U.S. Cybersecurity and Infrastructure Security Agency has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, confirming that attackers have used the flaws in real-world activity.

The issues affect different parts of the kernel: the TLS receive path, the AF_ALG cryptographic interface and the bridge Netfilter ebtables SNAT target. CISA required covered federal agencies to remediate all three on an accelerated timeline and called for forensic triage, not patching alone.

The three vulnerabilities

  • CVE-2025-39682, rated CVSS 9.8, involves incorrect handling of a zero-length record in the kernel TLS receive path. Under affected conditions, the flaw can create unsafe socket-buffer state and may lead to denial of service or memory disclosure.
  • CVE-2025-39964, rated CVSS 7.8, is a race condition in AF_ALG. Concurrent writes to the same socket can become interleaved, corrupting internal state and potentially causing crashes or incorrect cryptographic results.
  • CVE-2026-53266, rated CVSS 8.8, is an out-of-bounds write in the bridge Netfilter ebtables SNAT target. A crafted ARP-related path can lead to memory corruption outside the intended packet buffer.

CISA has not disclosed the threat actors, victims or exploitation chains associated with the flaws. KEV inclusion nevertheless establishes that exploitation has occurred.

Blue-team priorities

Administrators should use distribution-provided packages rather than relying only on generic upstream kernel version comparisons. After installing an update, systems generally need to reboot into the fixed kernel; teams should verify the running version rather than assuming the package installation completed remediation.

Before or alongside patching, defenders should preserve telemetry and investigate exposed systems for unexpected kernel crashes, privilege changes, namespace activity, netfilter modifications and other signs of compromise.

  • Identify systems using kernel TLS, AF_ALG or affected bridge Netfilter rules.
  • Prioritize internet-facing and multi-user hosts.
  • Apply vendor kernel updates and reboot.
  • Verify the active kernel after restart.
  • Use vendor mitigations or disable unused affected functionality where an update is not yet available.
  • Retire unsupported systems that cannot be remediated.

Sources

By Allan