CISA has added three Linux kernel vulnerabilities—CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266—to its Known Exploited Vulnerabilities catalog and is urging federal agencies to patch them within three days. The flaws can lead to denial-of-service, memory disclosure, system crashes, or memory corruption in the Linux kernel and related networking and cryptographic components. #CVE-2025-39682 #CVE-2025-39964 #CVE-2026-53266 #CISA
Keypoints
- CISA expanded its KEV catalog with three newly listed Linux kernel flaws.
- CVE-2025-39682 is a critical TLS receive path issue with a CVSS score of 9.8.
- CVE-2025-39964 is an AF_ALG socket race condition that can cause crashes or corrupted results.
- CVE-2026-53266 is an out-of-bounds write in the bridge Netfilter ebtables SNAT target.
- CISA told federal agencies to patch all three vulnerabilities within three days.
Read More: https://www.securityweek.com/organizations-warned-of-3-exploited-linux-kernel-vulnerabilities/