Thehackernews CISA Flags Active Exploitation of Linux Kernel Vulnerabilities
Article Content
- •CISA has flagged three Linux kernel vulnerabilities for active exploitation.
- •CVE-2025-39964 allows local attackers to exploit a race condition in AF_ALG sockets.
- •Federal agencies must apply patches by September 21, 2026, according to CISA.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including CVE-2025-39964, which allows local attackers to exploit a race condition in AF_ALG sockets. This vulnerability, along with CVE-2025-39682 and CVE-2026-53266, has been confirmed to be actively exploited in the wild. The vulnerabilities can lead to system crashes, denial-of-service (DoS), and privilege escalation. Red Hat has issued advisories urging immediate action to address these vulnerabilities. Federal agencies are advised to apply necessary fixes by September 21, 2026. The vulnerabilities primarily affect multi-tenant Linux servers, container hosts, and systems running untrusted local code. The risk is heightened in environments where operational technology is involved. The situation is evolving as researchers continue to monitor the exploitation methods.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track CVE-2025-39682 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…
CISA Urges Urgent Patching for Actively Exploited Linux Kernel Vulnerabilities The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has flagged three Linux kernel vulnerabilities as actively exploited, requiring federal agencies to patch them by September 21, 2026. The vulnerabilities, CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964, were added to CISA's Known Exploited…