CISA Adds Three Actively Exploited Linux Kernel Flaws to Its KEV Catalog
The US Cybersecurity and Infrastructure Security Agency added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on September 18. Being on that list means CISA has evidence of real attacks, not just a proof of concept.
Under Binding Operational Directive 26-04, US federal agencies were given unusually short deadlines to fix them. Everyone else should read the list the same way: these are being used.
The three CVEs
| CVE | CVSS | Subsystem | Impact |
|---|---|---|---|
| CVE-2025-39682 | 9.8 | Kernel TLS (kTLS) receive path | A zero-length record after a zero-copy decryption failure can disclose memory or crash the system |
| CVE-2026-53266 | 8.8 | Bridge netfilter, ebtables SNAT target | Out-of-bounds write when rewriting ARP, enabling denial of service or local privilege escalation |
| CVE-2025-39964 | 7.8 | AF_ALG crypto sockets | A race lets concurrent writes crash the system or corrupt cryptographic results |
Red Hat described at least one of them as high risk with “known public exploits leveraging this vulnerability.”
Two of these carry 2025 CVE numbers. They were fixed upstream a year ago. Their appearance on an exploited list in September 2026 says less about the kernel and more about how many machines still run kernels that never received those fixes.
The deadlines
| CVE | Internet-facing systems | Internal systems |
|---|---|---|
| CVE-2025-39682 | 3 days (September 21) | 3 days (September 21) |
| CVE-2026-53266 | September 21 | October 2 |
| CVE-2025-39964 | September 21 | October 2 |
The TLS bug got a three-day window for every asset regardless of exposure, which is as aggressive as KEV deadlines get.
Are you affected?
Kernel TLS is used by software that offloads TLS to the kernel for performance, which includes some web servers, storage protocols like NVMe/TCP, and anything using sendfile() over TLS. It is a loadable module (tls), so check whether it is in use:
lsmod | grep -E '^(tls|ebtable_nat|af_alg|algif_)'
ebtables matters on hosts that bridge traffic: virtualization hosts, container hosts with bridge networking, and routers. AF_ALG is the kernel crypto socket interface, used by some crypto libraries and cryptsetup benchmarks.
The real answer, though, is to update rather than audit. All three are fixed in current stable and distribution kernels. Our guide to checking whether your kernel is patched against a specific CVE shows how to confirm it against your distro’s tracker, which matters because distribution kernels backport fixes without bumping the upstream version.
# Debian / Ubuntu
sudo apt update && sudo apt full-upgrade
# Fedora / RHEL
sudo dnf upgrade --refresh
# Then actually boot the new kernel
sudo reboot
A kernel update does nothing until you reboot into it, unless you use live patching.
A busy week for kernel security
This landed the day after researcher Asim Manizada published working root exploits for four other kernel networking bugs. Neither set is related, but together they make the same point about keeping Linux updated: the dangerous window is not the time between disclosure and fix, it is the time between fix and reboot.