U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

Pierluigi Paganini
September 20, 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2025-39682 – Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
  • CVE-2025-39964 Linux Kernel Race Condition Vulnerability
  • CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability

Below are detailed descriptions of the flaws:

  • CVE-2025-39682 (CVSS score: 9.8) – A flaw in the TLS receive path that fails to properly handle unexpected conditions, potentially allowing authenticated local users to expose sensitive memory contents or cause a denial-of-service (DoS).
  • CVE-2026-53266 (CVSS score: 8.8) – A memory corruption issue in the ebtables SNAT ARP rewrite path that could let a local attacker cause unexpected system behavior, crash the system, or gain elevated privileges.
  • CVE-2025-39964 (CVSS score: 7.8) – A synchronization flaw affecting AF_ALG sockets that could allow simultaneous writes to interfere with each other, potentially crashing the system or affecting the integrity of cryptographic operations.

At the time of this writing, there are currently no details on how the three vulnerabilities are being exploited in the wild, or whether they are being used together as part of a single attack chain.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend that private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix the above vulnerabilities by September 21, 2026.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.