CISA KEV: three Linux kernel flaws (CVE-2025-39682 / CVE-2026-53266 / CVE-2025-39964); FCEB due 21 Sep
CISA added three Linux kernel vulnerabilities to the Known Exploited Vulnerabilities catalog on 18 September 2026 (catalog 2026.09.18), citing evidence of active exploitation. CVE-2025-39682 (NVD CVSS 3.1 9.8 Critical): improper check in the TLS receive path — zero-length records on rx_list can bypass intended recvmsg() record-type handling. CVE-2026-53266 (NVD 8.8 High): out-of-bounds write in ebtables SNAT ARP rewrite path. CVE-2025-39964 (NVD 7.8 High): race allowing concurrent writes to the same AF_ALG socket (crypto). CISA BOD 26-04 FCEB recommended due date 21 September 2026; ransomware use Unknown; forensic triage required per BOD notes. Distinct from the 18 Sep DirtyAH6/PPPoEject/TUNderflow/DiagSpill local-root quartet already on the desk. The Hacker News (19 Sep) reports Red Hat updated advisories acknowledging active exploitation / public exploits — apply distro kernel updates. Primary: CISA KEV; CVSS from NVD; secondary: THN / Red Hat CVE pages.
- Product
- Linux kernel (TLS rx_list / ebtables SNAT ARP / AF_ALG crypto sockets)
- Versions
- Long-standing kernel lines — apply distribution security updates that include the stable commits listed in CISA KEV notes / vendor advisories; discontinue EoL kernels
- CVSS
- (CVE-2025-39682 NVD CVSS 3.1 Critical); also 8.8 (CVE-2026-53266), 7.8 (CVE-2025-39964)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Install vendor/distro kernel security updates covering CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964; reboot into the patched kernel. FCEB: meet CISA BOD 26-04 due date 2026-09-21 and forensic-triage guidance in KEV notes.
Primary: CISA KEV — Linux kernel CVE-2025-39682 / CVE-2026-53266 / CVE-2025-39964 (added 18 Sep 2026) · Vendor: Red Hat — CVE-2025-39682 (also CVE-2026-53266 / CVE-2025-39964 on access.redhat.com) · CVE: CVE-2025-39682, CVE-2026-53266, CVE-2025-39964 · The Hacker News — CISA flags three Linux kernel vulns (19 Sep 2026); NVD for CVSS
