Find notable cyber news and cases, enriched with sources, timelines, and signals.

Linux kernel race condition, out-of-bounds write, and TLS flaw (multiple vulnerabilities)

Vulnerability
First reported
Last updated
Happening score
H score 36
1 unique sources, 1 articles

Summary

Hide ▲

Attackers are actively exploiting three Linux kernel vulnerabilities in AF_ALG, ebtables SNAT, and kTLS, and CISA has ordered urgent mitigation for federal systems. The flaws are CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682, spanning medium to critical severity and including a critical race condition, an out-of-bounds write, and a TLS receive-path logic flaw. Public exploits are available for two of the flaws, and one was demonstrated with privilege escalation and container escape.

Related Happenings

Linux kernel active exploitation wave (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682)

Exploitation Wave
H score35 First: 21.09.2026 23:12 Last: 21.09.2026 23:12 Sources 1

How related: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical.

About this happening: CISA has warned that three Linux kernel vulnerabilities are being exploited in attacks, including one critical flaw, creating immediate risk for exposed systems. The w...

CISA orders federal agencies to patch Linux kernel flaws

Public Sector Action
H score30 First: 21.09.2026 23:12 Last: 21.09.2026 23:12 Sources 1

How related: CISA marked all three flaws with the highest priority for federal agencies, ordering them to apply available security updates and mitigations by the end of today.

About this happening: CISA ordered federal agencies to apply security updates and mitigations for three Linux kernel flaws by end of today, putting the response on an urgent federal...

Linux kernel Dirty Frag local root escalation privilege-escalation flaw

Vulnerability
H score30 First: 08.05.2026 10:45 Last: 08.05.2026 10:45 Sources 1

About this happening: Dirty Frag is a newly disclosed Linux kernel zero-day that can give local attackers root privileges on most major Linux distributions. The flaw is anchored in the...

CISA KEV action for CVE-2026-31431 and FCEB remediation

Public Sector Action
H score37 First: 03.05.2026 09:26 Last: 03.05.2026 09:26 Sources 1

About this happening: CISA added CVE-2026-31431 to its KEV catalog, putting Federal Civilian Executive Branch (FCEB) agencies on notice to remediate an actively exploited Linux privilege-es...

Linux distributions mitigation advisories for CVE-2026-31431

Advisory/Mitigation
H score39 First: 30.04.2026 12:24 Last: 30.04.2026 12:24 Sources 1

About this happening: Multiple Linux distributions released advisories for CVE-2026-31431, adding mitigation guidance for a Linux kernel local privilege escalation that can let an unprivile...

Timeline

  1. 21.09.2026 23:12 2 articles · 1h ago

    CISA warns of active exploitation of three Linux kernel flaws

    Initial Disclosure

    CISA says attackers are actively exploiting CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682 in the Linux kernel, and it ordered federal agencies to apply available security updates and mitigations by the end of today while also requiring forensic triage for affected assets. The flaws include a race condition in the AF_ALG cryptographic socket interface, an out-of-bounds write in the ebtables SNAT implementation, and a TLS receive-path logic flaw in kTLS. STAR Labs identified CVE-2025-39964 and demonstrated privilege escalation and container escape in Google’s kernelCTF, while Red Hat confirmed public or known exploits for CVE-2025-39682 and CVE-2026-53266.

    Show sources