< Back to all clusters
[TECHNOLOGY] · United States · 8 sources

started · updated

Linux kernel vulnerabilities added to CISA KEV catalog

The Cybersecurity and Infrastructure Security Agency (CISA) has added three high-severity Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming they are being actively exploited in the wild. The vulnerabilities include CVE-2025-39682, which affects the TLS receive path and carries a CVSS score of 9.8; CVE-2026-53266, an out-of-bounds write in the ebtables SNAT ARP rewrite path with a CVSS score of 8.8; and CVE-2025-39964, a race condition in the AF_ALG cryptographic interface with a CVSS score of 7.8.

Notably, CVE-2025-39964 is a long-standing flaw that has existed in the kernel for approximately 14 to 15 years. Researchers from STAR Labs identified the issue, demonstrating that it could lead to local privilege escalation and container escapes.

CISA issued an urgent remediation deadline of September 21, 2026, for federal agencies. Security experts advise all Linux administrators, particularly those managing servers, containers, and IoT systems, to apply the latest kernel updates immediately to mitigate risks of memory disclosure, denial-of-service, and unauthorized privilege escalation.

Entities

CISA · Google · Linux · Linux kernel · Red Hat · STAR Labs

Claims

What the coverage asserts, and how many sources carry each claim.