CISA warns of ongoing exploitation of three Linux kernel vulnerabilities

CISA warns of ongoing exploitation of three Linux kernel vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the exploitation of three vulnerabilities in the Linux kernel, one of which is classified as critical.

These three security flaws were individually reported last week and have severity ratings that range from medium to critical. Notably, one of them, identified as CVE-2025-39964, has been present in the Linux kernel for 14 years.

CISA has designated all three vulnerabilities as high priority for federal agencies, instructing them to implement any available security updates and mitigations by the end of today.

The vulnerabilities are as follows:

  • CVE-2025-39964: A race condition in the kernel’s AF_ALG cryptographic socket interface that permits concurrent writes, potentially corrupting per-socket state and leading to system crashes or altered cryptographic outcomes.
  • CVE-2026-53266: An out-of-bounds write vulnerability in the Linux kernel’s ebtables SNAT implementation that can result in an ARP address rewrite, modifying shared file-backed memory without first making the affected packet range writable.
  • CVE-2025-39682: A flaw in the Linux kernel TLS receive-path logic that improperly handles zero-length records queued for later processing, which may allow different TLS record types to be processed together when kTLS is utilized.

CISA has indicated that these vulnerabilities have been exploited in attacks, although it has not disclosed specific details about the incidents or the identity of the threat actors.

The offensive security firm STAR Labs discovered CVE-2025-39964, stating that their researchers identified the issue without assistance from an AI system. They showcased the vulnerability by achieving privilege escalation and container escape in Google’s kernelCTF.

Public exploits are available for CVE-2025-39682, as confirmed by Red Hat in its security bulletin. Red Hat also acknowledged a known exploit for CVE-2026-53266.

Researcher Kimmo Suominen has shared a technical analysis and patch-status tracker for CVE-2026-53266 on GitHub, detailing a potential privilege-escalation path that involves modifications to file-backed memory. However, the researcher cautions that the suggested exploitation chain is inferred by analogy with Dirty Pipe and has not been demonstrated with publicly available exploit code.

CISA has classified all three vulnerabilities as requiring “forensic triage,” meaning that federal agencies must investigate each affected asset for indications of prior exploitation.

At present, none of the three vulnerabilities has been identified as being exploited by ransomware groups.

Build your security blueprint for AI-powered attacks. Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on the implications of AI-speed attacks, what defenders should cease doing, and how to validate, decide, fix, and re-validate at machine speed. Save your seat.

Source: Original article

Leave a Reply

Your email address will not be published. Required fields are marked *

Back To Top