BlackTree Security · Infrastructure · Automation · AI

CISA Gave Three Linux Kernel Bugs a Three-Day Deadline

Three Linux kernel vulnerabilities entered CISA’s Known Exploited Vulnerabilities catalogue on 18 September with a remediation date of 21 September. The three-day deadline is unusually short. It is also easy to misread: a shared catalogue date does not prove that the flaws belong to one campaign or affect the same systems.

VulnerabilityKernel areaOperational question
CVE-2025-39682Kernel TLS receive processingWhich supported distribution packages include the fix, and were affected kernels running during the exposed period?
CVE-2025-39964AF_ALG cryptographic socket race conditionCan an untrusted local process reach the affected interface, including through container or shared-host boundaries?
CVE-2026-53266Bridge netfilter ebtables SNAT out-of-bounds writeAre the affected networking components present and reachable in the running configuration?
CISA records active exploitation for each entry but does not publish a common actor, campaign or exploit chain.

Known exploitation is the fact. The campaign remains unknown.

CISA’s official KEV feed records the three additions and marks ransomware use as unknown. It does not disclose victims, indicators, initial-access routes or whether exploitation requires an existing local foothold. Defenders should not fill those gaps with assumptions.

Kernel exposure is also distribution-specific. An upstream version number does not reliably establish whether a Red Hat, Ubuntu, Debian, SUSE, cloud or appliance kernel is vulnerable because maintainers often backport individual fixes. The authoritative answer is the vendor’s package advisory and the exact running build.

Do not patch by CVE count

  • Inventory the running kernel. Record the active build, not only the installed package or the image used at deployment.
  • Use distribution guidance. Map each of the three entries separately to the package and fixed build supplied by the relevant vendor.
  • Prioritise shared and exposed systems. Containers, hosting platforms, build runners and multi-user servers make a local kernel primitive more consequential.
  • Reboot where required. A package update may leave the vulnerable kernel active until the host restarts.
  • Review the vulnerable period. Look for suspicious local execution, privilege changes, kernel crashes and unexpected networking changes.
  • Document exceptions. If a vendor says a product is not affected, keep the advisory and exact build evidence rather than relying on memory.

The 21 September date is a binding remediation deadline for covered US federal civilian agencies under the relevant federal directive. It is not automatically a legal deadline for every organisation. It is still a strong signal that CISA considers delay unacceptable where affected products remain in use.

The correct response is not one generic Linux ticket. Treat CVE-2025-39682, CVE-2025-39964 and CVE-2026-53266 as three separate exposure decisions, then prove that the fixed kernel is actually running.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *