Three Linux kernel flaws in KEV: verify the running kernel

Check distribution fixes, feature prerequisites and restart status for TLS, ebtables and AF_ALG issues.

Contents of this article

Exploitation is recorded

CISA added CVE-2025-39682, CVE-2026-53266 and CVE-2025-39964 on September 18, 2026. They concern TLS receive handling, an ebtables SNAT out-of-bounds write and an AF_ALG race. Their prerequisites differ; Linux use alone does not establish identical remote exposure.

Use distribution-specific fix status

Distributions may backport fixes. Record the distribution, package version, vendor advisory and running kernel, then assess relevant features. Provider host maintenance and updates inside a customer VM are separate responsibilities.

Containers require a host check

Rebuilding an application image may leave the affected host kernel unchanged. Review host isolation, node pools and placement, and plan rolling maintenance. Validate service dependencies before changing modules or network rules.

Installation is not the final check

After reboot or a supported remediation procedure, verify the active kernel and test forwarding, TLS and workloads. Investigate unexplained privilege changes or processes separately; patching does not remove an existing compromise.

References

CISA KEV catalog

Linux CVE records

Continue reading

Read related content

Back to industry insights Contact technical support