CISA added the three vulnerabilities to its Known Exploited Vulnerabilities catalog last week, marking them as high priority for federal networks. The agency has not detailed the attacks or the threat actors involved, but instructed affected agencies to conduct forensic triage on all relevant assets to check for signs of prior exploitation.
The three flaws span medium to critical severity. The most notable, CVE-2025-39964, is a race condition in the kernel's AF_ALG cryptographic socket interface that had existed for 14 years. It can allow concurrent writes to corrupt per-socket state, potentially crashing systems or altering cryptographic results. Offensive security firm STAR Labs, which found the flaw, demonstrated privilege escalation and container escape in Google's kernelCTF environment. The company emphasized its researchers discovered the issue without assistance from an AI system.
The second flaw, CVE-2026-53266, is an out-of-bounds write in the kernel's ebtables SNAT implementation. It can cause an ARP address rewrite to modify shared file-backed memory without first making the affected packet range writable. Researcher Kimmo Suominen has published a technical analysis and patch-status tracker on GitHub, outlining a potential privilege-escalation path. However, Suominen notes the exploitation chain is inferred by analogy with the Dirty Pipe vulnerability and has not been demonstrated with public exploit code.
The third flaw, CVE-2025-39682, is a Linux kernel TLS receive-path logic issue that mishandles zero-length records queued for later processing, potentially allowing different TLS record types to be processed together when kTLS is in use. Red Hat has confirmed that public exploits are available for this flaw and for CVE-2026-53266.
Currently, none of the three vulnerabilities is flagged as exploited by ransomware groups, according to CISA. Federal agencies have been ordered to apply available security updates and mitigations by the end of today.