CISA flags active exploitation of three Linux kernel flaws, orders federal fixes

Agencies told to patch by end of today; one vulnerability dates back 14 years

By LineZotpaper
Published
Read Time2 min
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that threat actors are actively exploiting three Linux kernel vulnerabilities, including one rated critical, and has ordered federal agencies to apply patches by the end of the day.

CISA added the three vulnerabilities to its Known Exploited Vulnerabilities catalog last week, marking them as high priority for federal networks. The agency has not detailed the attacks or the threat actors involved, but instructed affected agencies to conduct forensic triage on all relevant assets to check for signs of prior exploitation.

The three flaws span medium to critical severity. The most notable, CVE-2025-39964, is a race condition in the kernel's AF_ALG cryptographic socket interface that had existed for 14 years. It can allow concurrent writes to corrupt per-socket state, potentially crashing systems or altering cryptographic results. Offensive security firm STAR Labs, which found the flaw, demonstrated privilege escalation and container escape in Google's kernelCTF environment. The company emphasized its researchers discovered the issue without assistance from an AI system.

The second flaw, CVE-2026-53266, is an out-of-bounds write in the kernel's ebtables SNAT implementation. It can cause an ARP address rewrite to modify shared file-backed memory without first making the affected packet range writable. Researcher Kimmo Suominen has published a technical analysis and patch-status tracker on GitHub, outlining a potential privilege-escalation path. However, Suominen notes the exploitation chain is inferred by analogy with the Dirty Pipe vulnerability and has not been demonstrated with public exploit code.

The third flaw, CVE-2025-39682, is a Linux kernel TLS receive-path logic issue that mishandles zero-length records queued for later processing, potentially allowing different TLS record types to be processed together when kTLS is in use. Red Hat has confirmed that public exploits are available for this flaw and for CVE-2026-53266.

Currently, none of the three vulnerabilities is flagged as exploited by ransomware groups, according to CISA. Federal agencies have been ordered to apply available security updates and mitigations by the end of today.

§

Analysis

Why This Matters

  • These vulnerabilities are under active exploitation, posing immediate risk to systems running Linux kernels, especially in enterprise and government environments.
  • The 14-year-old nature of CVE-2025-39964 highlights long-standing weaknesses in critical infrastructure software, potentially affecting a wide range of devices.
  • Federal agencies have a very short window to patch, reflecting the urgency and potential for cascading impacts.

Background

CISA maintains a Known Exploited Vulnerabilities catalog to prioritize remediation for government networks, but the list is widely used by private sector organizations as a benchmark for patching urgency. Linux kernel flaws often require careful coordination among distributors and system administrators because patches can affect system stability. The vulnerabilities were disclosed over the past year, with fixes distributed across various Linux distributions.

Key Perspectives

Federal agencies: Must comply with the binding operational directive to remediate by the deadline, requiring rapid testing and deployment of patches.

Vendors and maintainers: Red Hat and others have confirmed exploits for some flaws, pushing them to release timely updates and advisories.

Security researchers: STAR Labs emphasized human-driven discovery in an era of AI-assisted methods, while Suominen's work provides transparency on potential exploitation chains, helping defenders assess risk.

What to Watch

  • Whether proof-of-concept code for CVE-2026-53266 emerges after patch availability, increasing exploitation risk for unpatched systems.
  • Any additional details from CISA or vendors about the observed attacks, which could reveal threat actor profiles.
  • Adoption of patches across enterprise and cloud environments, and any reports of intrusion attempts post-deadline.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.