CISA Gave Three Linux Kernel Bugs a Three-Day Deadline
Three Linux kernel vulnerabilities entered CISA’s Known Exploited Vulnerabilities catalogue on 18 September with a remediation date of 21 September. The three-day deadline is unusually short. It is also easy to misread: a shared catalogue date does not prove that the flaws belong to one campaign or affect the same systems.
| Vulnerability | Kernel area | Operational question |
|---|---|---|
| CVE-2025-39682 | Kernel TLS receive processing | Which supported distribution packages include the fix, and were affected kernels running during the exposed period? |
| CVE-2025-39964 | AF_ALG cryptographic socket race condition | Can an untrusted local process reach the affected interface, including through container or shared-host boundaries? |
| CVE-2026-53266 | Bridge netfilter ebtables SNAT out-of-bounds write | Are the affected networking components present and reachable in the running configuration? |
Known exploitation is the fact. The campaign remains unknown.
CISA’s official KEV feed records the three additions and marks ransomware use as unknown. It does not disclose victims, indicators, initial-access routes or whether exploitation requires an existing local foothold. Defenders should not fill those gaps with assumptions.
Kernel exposure is also distribution-specific. An upstream version number does not reliably establish whether a Red Hat, Ubuntu, Debian, SUSE, cloud or appliance kernel is vulnerable because maintainers often backport individual fixes. The authoritative answer is the vendor’s package advisory and the exact running build.
Do not patch by CVE count
- Inventory the running kernel. Record the active build, not only the installed package or the image used at deployment.
- Use distribution guidance. Map each of the three entries separately to the package and fixed build supplied by the relevant vendor.
- Prioritise shared and exposed systems. Containers, hosting platforms, build runners and multi-user servers make a local kernel primitive more consequential.
- Reboot where required. A package update may leave the vulnerable kernel active until the host restarts.
- Review the vulnerable period. Look for suspicious local execution, privilege changes, kernel crashes and unexpected networking changes.
- Document exceptions. If a vendor says a product is not affected, keep the advisory and exact build evidence rather than relying on memory.
The 21 September date is a binding remediation deadline for covered US federal civilian agencies under the relevant federal directive. It is not automatically a legal deadline for every organisation. It is still a strong signal that CISA considers delay unacceptable where affected products remain in use.
The correct response is not one generic Linux ticket. Treat CVE-2025-39682, CVE-2025-39964 and CVE-2026-53266 as three separate exposure decisions, then prove that the fixed kernel is actually running.
Sources
- CISA Known Exploited Vulnerabilities catalogue JSON, the authoritative machine-readable record for all three entries, added 18 September 2026 with due date 21 September. Individual entry times were not provided.
- CISA alert for the race-condition and out-of-bounds-write entries, released 18 September 2026. The catalogue JSON separately records the kernel TLS entry and the same deadline.


