CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog
CISA expanded its Known Exploited Vulnerabilities catalog with three Linux kernel flaws: CVE-2025-39682 (CVSS 9.8, TLS receive-path memory disclosure and DoS), CVE-2025-39964 (CVSS 7.8, AF_ALG socket race) and CVE-2026-53266 (CVSS 8.8, ebtables SNAT out-of-bounds write). US federal agencies must patch all three within three days.
- CVE-2025-39682 (CVSS 9.8) is a critical flaw in the kernel TLS receive path
- CVE-2025-39964 (CVSS 7.8) is a race condition in AF_ALG socket writes
- CVE-2026-53266 (CVSS 8.8) is an out-of-bounds write in ebtables SNAT
- US federal agencies have three days to apply the patches
Read next
Security