TL;DR
CISA confirmed active attacks targeting three distinct Linux kernel flaws. The vulnerabilities involve race conditions in cryptographic sockets, memory corruption in network packet filters, and a flaw in the kernel’s TLS record handling. System operators should apply vendor updates or disable vulnerable modules immediately.
- Product: Linux
- Vulnerabilities: 3 flaws (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682)
- Highest severity: 9.8 (Critical Β· CVSSv3)
- Worst impact: tls: fix handling of zero-length records on the rx_list
- Status: 3 exploited; patches available
- Exploit Intel (PatchThis): 3 of 3 confirmed
- Action: Update to 0f28c4adbc4a97437874c9b669fd7958a8c6d6ce, e4c1ec11132ec466f7362a95f36a506ce4dc08c9, 1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8, 7c4491b5644e3a3708f3dbd7591be0a570135b84 (+38) now
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2025-39682 | 9.8 | NVD-CWE-Other | 2902c3ebcca52ca845c03182000e8d71d3a5196f, c09dd3773b5950e9cfb6c9b9a5f6e36d06c62677, 3439c15ae91a517cf3c650ea15a8987699416ad9 (+7) | Exploited |
| CVE-2026-53266 | 8.8 | NVD-CWE-noinfo | bf84ad7c7a9ede46e31afaa41a1ba06a159e8c87, 76280b78cc9f23bdc6438e10ad6dff148ef8375b, b7e91939ba9be805a62a257fa4e227dffbb88fa0 (+16) | Exploited |
| CVE-2025-39964 | 7.8 | NVD-CWE-noinfo | 0f28c4adbc4a97437874c9b669fd7958a8c6d6ce, e4c1ec11132ec466f7362a95f36a506ce4dc08c9, 1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8 (+11) | Exploited |
Running Infra, AppSec, and SOC teams? Tag Linux kernel alerts by team automatically.
Try Team free for 14 daysWhy This Matters
Industry estimates indicate that Linux powers billions of cloud instances, enterprise servers, and connected devices worldwide. Therefore, flaws within core kernel subsystems create serious security risks for critical infrastructure. Because threat actors are exploiting these weaknesses in the wild, unpatched systems face immediate danger. Attackers can destabilize production environments or escalate local user accounts into full administrative control.
How the Attacks Work
The first flaw, CVE-2025-39964, stems from a race condition inside the kernel cryptographic user API. The advisory notes: “The AF_ALG datapath allowed two writers on the same socket, causing request payloads to interleave unpredictably.” As a result, this flaw can corrupt cryptographic results or cause denial-of-service conditions.
The second vulnerability, CVE-2026-53266, affects the netfilter bridge ebtables module. The advisory warns: “An Important flaw in the Linux kernel’s ebtables SNAT target allows a local attacker to achieve privilege escalation.” When rewriting address ranges in nonlinear network fragments, the driver copies data into memory pages without confirming write access.
The third flaw, CVE-2025-39682, sits in the kernel’s TLS receive path. It stems from the mishandling of zero-length records on the rx_list queue. According to the kernel fix, each recvmsg() call must process either contiguous data records or a single non-data record. A corner case appears when the first queued record is zero length, which the code failed to handle correctly. CISA lists it as an improper check for unusual or exceptional conditions.
Affected Versions
These Linux kernel vulnerabilities impact numerous production Linux distributions running unpatched kernel trees. Specifically, the issues affect systems with active cryptographic user APIs or customized bridge packet filters.
Patch and Mitigation Steps
Administrators must deploy the latest distribution updates immediately to secure their endpoints. In their advisories, officials urged organizations to review both the two-CVE catalog update and the same-day single-CVE addition for the TLS flaw. If immediate updates are impractical, teams should apply temporary mitigations. For the cryptographic flaw, administrators can blacklist the af_alg kernel module. Meanwhile, operators can mitigate the netfilter issue by disabling ARP hardware address rewriting in ebtables rules.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!