CISA is warning that attackers are actively exploiting three Linux kernel vulnerabilities, including CVE-2025-39964, which has existed for 14 years and is rated critical. Federal agencies must patch and perform forensic triage immediately, while Red Hat and researchers have confirmed public or known exploits for CVE-2025-39682 and CVE-2026-53266. #CVE-2025-39964 #CVE-2026-53266 #CVE-2025-39682 #LinuxKernel #CISA
Keypoints
- CISA says three Linux kernel flaws are being exploited in attacks.
- CVE-2025-39964 is a critical race condition in the AF_ALG socket interface.
- CVE-2026-53266 can enable an out-of-bounds write in ebtables SNAT.
- CVE-2025-39682 affects TLS receive-path handling in kTLS.
- Federal agencies must patch the flaws and perform forensic triage by today.