AI Weekly Malaysia

Back to items Summaries

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

ID
26266
Status
summarized
Published
19 Sep 2026, 2:24 PM
Fetched
19 Sep 2026, 3:23 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
5.5
Created
19 Sep 2026, 3:23 PM
Tags
Audience
developersdatabase_learners

What happened

CISA added three actively exploited Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog on September 19, 2026: CVE-2025-39682 (CVSS 9.8, TLS receive path memory disclosure/DoS), CVE-2026-53266 (CVSS 8.8, ebtables SNAT ARP out-of-bounds write enabling local privilege escalation), and CVE-2025-39964 (CVSS 7.8, AF_ALG socket race condition corrupting crypto operations). Red Hat confirmed public exploits exist and flagged them as high priority; FCEB agencies face a September 21, 2026 patching deadline. All three require local authenticated access.

Why it matters

If you operate Linux servers or containers with multi-tenant or untrusted local users, patch these now—Red Hat says public exploits exist and CVE-2025-39682's 9.8 CVSS reflects trivial memory disclosure via the TLS receive path. For single-tenant dev boxes or sealed containers with no local untrusted access, the practical risk is lower since all three require local authentication. Check whether your distro has backported fixes yet rather than waiting for the next routine update cycle.

Discussion angle

How many of us actually know which kernel version our production servers and CI runners are on right now, and whether our distro has shipped patched kernels—versus just assuming cloud providers handle it?

Top