Three Linux kernel flaws in KEV: verify the running kernel
Check distribution fixes, feature prerequisites and restart status for TLS, ebtables and AF_ALG issues.
Contents of this article
Exploitation is recorded
CISA added CVE-2025-39682, CVE-2026-53266 and CVE-2025-39964 on September 18, 2026. They concern TLS receive handling, an ebtables SNAT out-of-bounds write and an AF_ALG race. Their prerequisites differ; Linux use alone does not establish identical remote exposure.
Use distribution-specific fix status
Distributions may backport fixes. Record the distribution, package version, vendor advisory and running kernel, then assess relevant features. Provider host maintenance and updates inside a customer VM are separate responsibilities.
Containers require a host check
Rebuilding an application image may leave the affected host kernel unchanged. Review host isolation, node pools and placement, and plan rolling maintenance. Validate service dependencies before changing modules or network rules.
Installation is not the final check
After reboot or a supported remediation procedure, verify the active kernel and test forwarding, TLS and workloads. Investigate unexplained privilege changes or processes separately; patching does not remove an existing compromise.
