CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog
The U.S. Cybersecurity agency CISA has mandated patching for three actively exploited Linux kernel vulnerabilities, including a critical flaw with a CVSS

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch three Linux kernel vulnerabilities that are being actively exploited. The flaws, which cover denial-of-service, memory corruption, and cryptographic corruption risks, must be addressed within three days, according to the agency's directive.
CISA added the three bugs to its Known Exploited Vulnerabilities (KEV) catalog but has not disclosed specific details about the in-the-wild attacks. The advisory shows the immediate risk these kernel-level defects pose to government systems.
Critical TLS Handling Flaw
The most severe of the three is CVE-2025-39682, a critical vulnerability with a CVSS score of 9.8. It resides in the kernel's handling of zero-length records within the rx_list on the TLS receive path. The issue is a corner case in the recvmsg() logic, which processes either DATA or non-DATA records. The processing loop can break when an initial zero-length record is pulled from the rx_list.
During zero-copy decryption, the kernel decrypts ciphertext directly into a user-space buffer. Zero-copy operations are only permitted with DATA records, and the vulnerable function assumes no record type change can occur afterward. An attacker can break this logic using a crafted zero-length record from the rx_list. A local attacker could exploit this improper check for exceptional conditions to cause a denial-of-service condition or trigger memory disclosure.
Race Condition in AF_ALG Socket
The second vulnerability, tracked as CVE-2025-39964, carries a CVSS score of 7.8. CISA describes it as a race condition in the AF_ALG socket interface. Issuing two writes to the same AF_ALG socket can cause data to be interleaved unpredictably.
An attacker could trigger this security defect to create inconsistencies in the socket's internal state. This could lead to system crashes or produce corrupted results from cryptographic operations, ultimately causing denial-of-service conditions.
Out-of-Bounds Write in Netfilter
The third flaw added to the KEV catalog is CVE-2026-53266, an out-of-bounds write issue with a CVSS score of 8.8. The vulnerability exists in the bridge Netfilter ebtables Source Network Address Translation (SNAT) target.
Under certain conditions, an Address Resolution Protocol (ARP) sender hardware address is written directly into a nonlinear socket-buffer fragment. This action causes memory corruption. An attacker can trigger this unsafe write with a crafted packet containing a malicious ARP payload, leading to unauthorized memory modification outside the intended packet buffer.
The following table compares the three vulnerabilities based on the information provided by CISA and SecurityWeek:
| CVE Identifier | CVSS Score | Vulnerability Type | Primary Impact |
|---|---|---|---|
| CVE-2025-39682 | 9.8 | Improper check for exceptional conditions in TLS receive path | Denial-of-service, memory disclosure |
| CVE-2025-39964 | 7.8 | Race condition in AF_ALG socket | Denial-of-service, cryptographic corruption |
| CVE-2026-53266 | 8.8 | Out-of-bounds write in bridge Netfilter ebtables SNAT target | Memory corruption |
CISA's binding operational directive requires federal civilian executive branch agencies to apply vendor-issued patches for these vulnerabilities within the three-day deadline. The agency has not shared details on the exploitation of the three vulnerabilities, but told federal agencies they should patch all three within three days.





