Linux kernel race condition, out-of-bounds write, and TLS flaw (multiple vulnerabilities)
Vulnerability
Summary
Hide ▲
Show ▼
Attackers are actively exploiting three Linux kernel vulnerabilities in AF_ALG, ebtables SNAT, and kTLS, and CISA has ordered urgent mitigation for federal systems. The flaws are CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682, spanning medium to critical severity and including a critical race condition, an out-of-bounds write, and a TLS receive-path logic flaw. Public exploits are available for two of the flaws, and one was demonstrated with privilege escalation and container escape.
Related Happenings
Linux kernel active exploitation wave (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682)
Exploitation Wave
H score35
First: 21.09.2026 23:12
Last: 21.09.2026 23:12
Sources 1
How related:
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical.
About this happening:
CISA has warned that three Linux kernel vulnerabilities are being exploited in attacks, including one critical flaw, creating immediate risk for exposed systems. The w...
Linux kernel active exploitation wave (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682)
Exploitation WaveHow related: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical.
About this happening: CISA has warned that three Linux kernel vulnerabilities are being exploited in attacks, including one critical flaw, creating immediate risk for exposed systems. The w...
CISA orders federal agencies to patch Linux kernel flaws
Public Sector Action
H score30
First: 21.09.2026 23:12
Last: 21.09.2026 23:12
Sources 1
How related:
CISA marked all three flaws with the highest priority for federal agencies, ordering them to apply available security updates and mitigations by the end of today.
About this happening:
CISA ordered federal agencies to apply security updates and mitigations for three Linux kernel flaws by end of today, putting the response on an urgent federal...
CISA orders federal agencies to patch Linux kernel flaws
Public Sector ActionHow related: CISA marked all three flaws with the highest priority for federal agencies, ordering them to apply available security updates and mitigations by the end of today.
About this happening: CISA ordered federal agencies to apply security updates and mitigations for three Linux kernel flaws by end of today, putting the response on an urgent federal...
Linux kernel Dirty Frag local root escalation privilege-escalation flaw
Vulnerability
H score30
First: 08.05.2026 10:45
Last: 08.05.2026 10:45
Sources 1
About this happening:
Dirty Frag is a newly disclosed Linux kernel zero-day that can give local attackers root privileges on most major Linux distributions. The flaw is anchored in the...
Linux kernel Dirty Frag local root escalation privilege-escalation flaw
VulnerabilityAbout this happening: Dirty Frag is a newly disclosed Linux kernel zero-day that can give local attackers root privileges on most major Linux distributions. The flaw is anchored in the...
CISA KEV action for CVE-2026-31431 and FCEB remediation
Public Sector Action
H score37
First: 03.05.2026 09:26
Last: 03.05.2026 09:26
Sources 1
About this happening:
CISA added CVE-2026-31431 to its KEV catalog, putting Federal Civilian Executive Branch (FCEB) agencies on notice to remediate an actively exploited Linux privilege-es...
CISA KEV action for CVE-2026-31431 and FCEB remediation
Public Sector ActionAbout this happening: CISA added CVE-2026-31431 to its KEV catalog, putting Federal Civilian Executive Branch (FCEB) agencies on notice to remediate an actively exploited Linux privilege-es...
Linux distributions mitigation advisories for CVE-2026-31431
Advisory/Mitigation
H score39
First: 30.04.2026 12:24
Last: 30.04.2026 12:24
Sources 1
About this happening:
Multiple Linux distributions released advisories for CVE-2026-31431, adding mitigation guidance for a Linux kernel local privilege escalation that can let an unprivile...
Linux distributions mitigation advisories for CVE-2026-31431
Advisory/MitigationAbout this happening: Multiple Linux distributions released advisories for CVE-2026-31431, adding mitigation guidance for a Linux kernel local privilege escalation that can let an unprivile...
Timeline
-
21.09.2026 23:12 2 articles · 1h ago
CISA warns of active exploitation of three Linux kernel flaws
Initial DisclosureCISA says attackers are actively exploiting CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682 in the Linux kernel, and it ordered federal agencies to apply available security updates and mitigations by the end of today while also requiring forensic triage for affected assets. The flaws include a race condition in the AF_ALG cryptographic socket interface, an out-of-bounds write in the ebtables SNAT implementation, and a TLS receive-path logic flaw in kTLS. STAR Labs identified CVE-2025-39964 and demonstrated privilege escalation and container escape in Google’s kernelCTF, while Red Hat confirmed public or known exploits for CVE-2025-39682 and CVE-2026-53266.
Show sources
- CISA alerts of active exploitation of three Linux kernel flaws — www.bleepingcomputer.com — 21.09.2026 23:12
- CISA alerts of active exploitation of three Linux kernel flaws — www.bleepingcomputer.com — 21.09.2026 23:12