CISA Warns of Active Exploitation of Three Linux Kernel Vulnerabilities
The US Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are actively exploiting three vulnerabilities in the Linux kernel, including one rated critical.
CISA added the three Linux kernel security flaws separately to its Known Exploited Vulnerabilities catalog last week. Their severity ratings range from moderate to critical. One of the vulnerabilities, tracked as CVE-2025-39964, has existed in the Linux kernel for 14 years.
CISA made all three vulnerabilities a top priority for federal agencies and ordered them to apply available security updates and mitigations immediately. Agencies must also investigate affected systems for evidence of compromise.
Three Linux kernel vulnerabilities added to CISA’s catalog
- CVE-2025-39964: A race condition in the kernel’s AF_ALG encrypted socket interface allows concurrent writes to corrupt per-socket state. This could cause a system crash or produce altered encryption results.
- CVE-2026-53266: An out-of-bounds write vulnerability in the Linux kernel’s ebtables SNAT implementation allows shared file backup memory to be modified through ARP address rewriting without first making the affected packet range writable.
- CVE-2025-39682: A flaw in the Linux kernel TLS receive path can cause zero-length records queued for later processing to be handled incorrectly. When using kTLS, different TLS record types could be processed together.
CISA says the vulnerabilities have been exploited in attacks, but it has not disclosed details about the incidents or the identities of the attackers. The agency’s alerts are available in its first and second advisories.
CVE-2025-39964 demonstrated in kernelCTF
Offensive security firm STAR Labs discovered CVE-2025-39964. The researchers said they found the vulnerability without assistance from an AI system and demonstrated it in Google’s kernelCTF environment.
The demonstration enabled privilege escalation and container escape, showing how the Linux kernel flaw could potentially allow an attacker to move beyond the privileges of an affected process or container.
Public exploit information available for two vulnerabilities
A public exploit is available for CVE-2025-39682, and Red Hat has confirmed the issue in its security bulletin.
Red Hat has also identified known exploits associated with CVE-2026-53266 in its security advisory.
Researcher Kimmo Suominen has published a CVE-2026-53266 patch status tracker on GitHub. The analysis outlines a potential privilege escalation path involving changes to file backup memory.
However, the proposed exploit chain is inferred by analogy from Dirty Pipe and has not been demonstrated with publicly available exploit code, according to the researcher’s technical notes.
CISA orders forensic triage of affected systems
CISA marks all three Linux kernel vulnerabilities as requiring “forensic triage.” This means federal agencies must examine affected assets for signs that exploitation has already occurred.
To date, none of the three vulnerabilities have been reported as being exploited by ransomware groups.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



