Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities

Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
CISA has added three Linux kernel vulnerabilities—CVE-2025-39682, CVE-2025-39964, and CVE-2026-53266—to its Known Exploited Vulnerabilities catalog and is urging federal agencies to patch them within three days. The flaws can lead to denial-of-service, memory disclosure, system crashes, or memory corruption in the Linux kernel and related networking and cryptographic components. #CVE-2025-39682 #CVE-2025-39964 #CVE-2026-53266 #CISA

Keypoints

  • CISA expanded its KEV catalog with three newly listed Linux kernel flaws.
  • CVE-2025-39682 is a critical TLS receive path issue with a CVSS score of 9.8.
  • CVE-2025-39964 is an AF_ALG socket race condition that can cause crashes or corrupted results.
  • CVE-2026-53266 is an out-of-bounds write in the bridge Netfilter ebtables SNAT target.
  • CISA told federal agencies to patch all three vulnerabilities within three days.

Read More: https://www.securityweek.com/organizations-warned-of-3-exploited-linux-kernel-vulnerabilities/