CISA Adds Three Actively Exploited Linux Kernel Flaws to Its KEV Catalog

CISA Adds Three Actively Exploited Linux Kernel Flaws to Its KEV Catalog

The US Cybersecurity and Infrastructure Security Agency added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on September 18. Being on that list means CISA has evidence of real attacks, not just a proof of concept.

Under Binding Operational Directive 26-04, US federal agencies were given unusually short deadlines to fix them. Everyone else should read the list the same way: these are being used.

The three CVEs

CVECVSSSubsystemImpact
CVE-2025-396829.8Kernel TLS (kTLS) receive pathA zero-length record after a zero-copy decryption failure can disclose memory or crash the system
CVE-2026-532668.8Bridge netfilter, ebtables SNAT targetOut-of-bounds write when rewriting ARP, enabling denial of service or local privilege escalation
CVE-2025-399647.8AF_ALG crypto socketsA race lets concurrent writes crash the system or corrupt cryptographic results

Red Hat described at least one of them as high risk with “known public exploits leveraging this vulnerability.”

Two of these carry 2025 CVE numbers. They were fixed upstream a year ago. Their appearance on an exploited list in September 2026 says less about the kernel and more about how many machines still run kernels that never received those fixes.

The deadlines

CVEInternet-facing systemsInternal systems
CVE-2025-396823 days (September 21)3 days (September 21)
CVE-2026-53266September 21October 2
CVE-2025-39964September 21October 2

The TLS bug got a three-day window for every asset regardless of exposure, which is as aggressive as KEV deadlines get.

Are you affected?

Kernel TLS is used by software that offloads TLS to the kernel for performance, which includes some web servers, storage protocols like NVMe/TCP, and anything using sendfile() over TLS. It is a loadable module (tls), so check whether it is in use:

lsmod | grep -E '^(tls|ebtable_nat|af_alg|algif_)'

ebtables matters on hosts that bridge traffic: virtualization hosts, container hosts with bridge networking, and routers. AF_ALG is the kernel crypto socket interface, used by some crypto libraries and cryptsetup benchmarks.

The real answer, though, is to update rather than audit. All three are fixed in current stable and distribution kernels. Our guide to checking whether your kernel is patched against a specific CVE shows how to confirm it against your distro’s tracker, which matters because distribution kernels backport fixes without bumping the upstream version.

# Debian / Ubuntu
sudo apt update && sudo apt full-upgrade
# Fedora / RHEL
sudo dnf upgrade --refresh
# Then actually boot the new kernel
sudo reboot

A kernel update does nothing until you reboot into it, unless you use live patching.

A busy week for kernel security

This landed the day after researcher Asim Manizada published working root exploits for four other kernel networking bugs. Neither set is related, but together they make the same point about keeping Linux updated: the dangerous window is not the time between disclosure and fix, it is the time between fix and reboot.

Background reading

Explainers for the concepts behind this story.