CISA Adds Three Critical Linux Kernel Flaws to Known Exploited Vulnerabilities Catalog
What Happened – The U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed three high‑severity Linux kernel vulnerabilities (CVE‑2025‑39682, CVE‑2025‑39964, CVE‑2026‑53266) in its Known Exploited Vulnerabilities (KEV) catalog. The flaws involve improper condition checks, a race condition, and an out‑of‑bounds write, each with CVSS scores ranging from 7.8 to 9.8.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous vulnerability monitoring and rapid patching to satisfy the “Vulnerability Management” control objective across frameworks.
- Provides a concrete trigger for evidence collection (e.g., patch‑status reports) that can be presented in audits or third‑party assessments.
- Highlights the importance of a control‑mapping capability that aligns remediation actions with the Verisq Common Framework (VCF) and NIST CSF 2.0.
Who Is Affected – Cloud‑infrastructure providers, SaaS platforms, and any organization that runs Linux‑based servers or containers, spanning sectors such as technology, finance, healthcare, and government.
Recommended Actions
- Verify whether any of the listed CVEs affect your Linux kernel version.
- Prioritize patching or applying mitigations before the CISA deadline (Sept 21 2026).
- Record remediation steps in a continuous control‑assurance system to generate defensible audit evidence.
Technical Notes –
- CVE‑2025‑39682: TLS receive path mishandles unexpected conditions, allowing local users to read memory or cause DoS (CVSS 9.8).
- CVE‑2025‑39964: Race condition in AF_ALG sockets may corrupt cryptographic operations (CVSS 7.8).
- CVE‑2026‑53266: Out‑of‑bounds write in ebtables SNAT ARP rewrite path can lead to privilege escalation (CVSS 8.8).
Source: SecurityAffairs article