- The Three Linux Kernel CVEs in KEV
- CVE-2025-39682 | Linux Kernel TLS Zero-Length Record Vulnerability
- CVE-2026-53266 | Linux Kernel Netfilter ebtables SNAT Vulnerability
- CVE-2025-39964 | Linux Kernel AF_ALG Socket Race Condition
- Why This Matters
- Our Recommendation: Deploy the Kernel Updates with Qualys TruRisk Eliminate
- Related
Executive Summary
CISA added three actively exploited Linux kernel vulnerabilities: CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to its KEV Catalog on September 18, 2026, triggering a 3-day remediation deadline that passed on September 21. Under CISA BOD 26-04, a 3-day window applies to CVE-2025-39682 across all assets, and for the other two, the deadline is 3 days for publicly exposed assets and 14 days for internal assets. With the September 21 deadline now passed, affected systems should be patched immediately. Qualys TruRisk Eliminate identifies affected assets with vulnerability context and provides High-Reliability Patches to support remediation and verification.
The Three Linux Kernel CVEs in KEV
Red Hat has updated its advisories for all three to acknowledge active exploitation and reports that public exploits are known.
Observed exposure across organizations shows these vulnerabilities can affect a substantial number of systems, including internet-facing assets, making timely remediation essential.
CVE-2025-39682 | Linux Kernel TLS Zero-Length Record Vulnerability
A flaw in how the kernel’s TLS receive path handles zero-length records. After zero-copy decryption, a crafted zero-length record can break the logic that assumes the record type cannot change, resulting in memory disclosure or a denial of service. It carries the highest severity of the three.
CVE-2026-53266 | Linux Kernel Netfilter ebtables SNAT Vulnerability
An out-of-bounds write in the bridge Netfilter ebtables SNAT target. A crafted packet with an ARP payload can make the kernel write outside the intended packet buffer, corrupting memory. Depending on the conditions, this can lead to denial-of-service or local privilege escalation.
CVE-2025-39964 | Linux Kernel AF_ALG Socket Race Condition
A race condition in the AF_ALG socket interface. Two writes to the same socket can interleave unpredictably, leaving the socket in an inconsistent state and causing a system crash or corrupted cryptographic results.
Average number of affected assets observed across organizationsUnder CISA BOD 26-04, the remediation window is either 3 or 14 days, depending on the CVE classification and whether the affected asset is publicly exposed.
For assets subject to the 3-day requirement, the September 21 deadline has passed. Therefore, these assets should be prioritized for patching to ensure compliance with the required remediation timeline. Qualys TruRisk Eliminate offers the necessary visibility needed to identify addressable exposure and move these systems toward remediation.
BOD 26-04 remediation deadlines by CVE classificationWhy This Matters
A KEV (Known Exploited Vulnerability) listing indicates that exploitation has been confirmed, rather than being merely theoretical. CISA also marked all three flaws as requiring forensic triage. These vulnerabilities exist in the Linux kernel, the core component of the host system. This means that successful exploitation could potentially affect the entire system rather than just a single application. Therefore, kernel-level vulnerabilities demand immediate attention and remediation to prevent any compromise from penetrating deeper into the host.
Our Recommendation: Deploy the Kernel Updates with Qualys TruRisk Eliminate
It’s important to patch immediately, starting with exposed assets. TruRisk Eliminate assists teams in moving from identifying vulnerable Linux assets to selecting the appropriate patches for remediation. For kernel vulnerabilities, it highlights the available High-Reliability Patches, giving teams greater confidence to accelerate remediation while reducing concerns about patch-related disruption.
Teams can then deploy the chosen kernel updates, perform the necessary reboot, and verify the remediation status to confirm that the vulnerabilities have been successfully addressed.
See which of your Linux assets are still exposed. Start a free trial of Qualys TruRisk Eliminate.

