Skip to content

Security6 publishers2 min readPublished

CISA gives agencies one business day to patch three exploited Linux kernel flaws

The three kernel CVEs CISA added to its exploited-bugs catalog on Friday all need local access, and the lowest-scored of them is the one STAR Labs used for privilege escalation and container escape. Red Hat has confirmed public exploit code.

The Watch · Security desk

Illustration accompanying CISA gives agencies one business day to patch three exploited Linux kernel flaws

What happened

  • CISA added CVE-2025-39682, CVE-2026-53266 and CVE-2025-39964 to its Known Exploited Vulnerabilities catalog on Friday, citing evidence of active exploitation, with a federal due date of September 21, 2026.
  • CVE-2025-39964, a race condition in the kernel's AF_ALG cryptographic socket interface, had been in the Linux kernel for 14 years before STAR Labs reported it.
  • Red Hat updated its advisories for all three flaws as of September 19 at 2 a.m. UTC to acknowledge active exploitation.
  • CISA also marked all three as requiring forensic triage, so agencies must examine every affected asset for signs that exploitation already occurred.
  • None of the three is currently flagged in the catalog as exploited by ransomware groups.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint All three need code already running on the host. They upgrade a foothold to root or out of a container, and the exposure lives in host and image inventory, not in perimeter scan results.
  • cost The triage half of the order costs more than the patch half: logs and disk images for every Linux host in scope, on the same deadline, from the same staff who are applying the kernel updates.
  • exposure A working container escape puts multi-tenant container hosts in scope, where one compromised workload reaches the kernel every other tenant on the box shares.
  • contradiction Security Affairs cites BOD 22-01 for the September 21 date while The Hacker News cites BOD 26-04; under the first the fix is required, under the second it is recommended, and an agency reading only one has a different obligation.

Rank the three by what an attacker has been shown to do with them and the severity order inverts. CVE-2025-39682 holds the 9.8 and the public exploit code, and its documented outcomes are memory disclosure or denial of service for a local authenticated user [3][9]. CVE-2025-39964 holds a 7.8, and STAR Labs used it to escalate privileges and escape a container in Google's kernelCTF [5][8].

The AF_ALG flaw needs two writes to the same cryptographic socket. The data interleaves unpredictably and leaves the socket's internal state inconsistent enough to crash the machine or corrupt the result of a cryptographic operation [27][5]. STAR Labs said its researchers found the issue with no help from an AI system [7].

CVE-2026-53266 is where public evidence and vendor language diverge. The bug writes an ARP sender hardware address straight into a nonlinear socket-buffer fragment, and a crafted packet carrying an ARP payload is enough to trigger the out-of-bounds write [26]. Red Hat confirmed that a known exploit exists [10]. Kimmo Suominen has published a technical analysis and a patch-status tracker on GitHub that sketches a privilege-escalation path through modification of file-backed memory, and he notes that the chain is inferred by analogy with Dirty Pipe and has not been demonstrated with public exploit code [19][20].

"This CVE is high risk and there are known public exploits leveraging this vulnerability," Red Hat said in its updated advisories. "Address this vulnerability with high priority." [12]

The window was three calendar days, two of them a weekend, which leaves one business day for any agency that does not run weekend change windows [24]. SecurityWeek described the order as patching all three within three days [15]. BleepingComputer, publishing on the due date, described the deadline as the end of that day [16]. CISA has not described the incidents, the actors, or whether the three were used together in one chain [18].

Separately from the KEV additions, researcher Asim Manizada disclosed four local privilege escalation flaws in the Linux kernel: CVE-2026-80844 (DirtyAH6), CVE-2026-81000 (TUNderflow), CVE-2026-68121 (PPPoEject) and CVE-2026-74469 (DiagSpill) [21].

What to watch

  • Whether CISA publishes exploitation details or ties any of the three CVEs to a named actor or intrusion set.
  • Whether public exploit code appears for the CVE-2026-53266 privilege-escalation chain that Suominen currently infers from Dirty Pipe.
  • Whether any of the three picks up a ransomware-use flag in the KEV catalog.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories