CVE-2025-39964 existed in the Linux kernel for 14 years.
CISA escalates three kernel flaws to highest federal priority
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned that hackers are exploiting three separate Linux kernel vulnerabilities and has marked all three with the highest priority for federal agencies. CISA ordered agencies to apply available security updates and mitigations by the end of today and to perform “forensic triage” on every affected asset to determine whether exploitation already occurred. The agency also said the vulnerabilities have been exploited in attacks but did not disclose details about the incidents or the threat actors involved.
The three vulnerabilities: brief technical summaries
CISA and vendor notices list the flaws as:
- CVE-2025-39964 — a race condition in the kernel’s AF_ALG cryptographic socket interface that allows concurrent writes to corrupt per-socket state and potentially crash systems or alter cryptographic results.
- CVE-2026-53266 — an out‑of‑bounds write in the kernel’s ebtables SNAT implementation that can cause an ARP address rewrite to modify shared file‑backed memory without first making the affected packet range writable.
- CVE-2025-39682 — a Linux kernel TLS (kTLS) receive‑path logic flaw that mishandles zero‑length records queued for later processing, potentially allowing different TLS record types to be processed together when kTLS is in use.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleWho found what: STAR Labs, Red Hat, and Kimmo Suominen
Offensive security company STAR Labs discovered CVE-2025-39964 and said its researchers demonstrated the issue by achieving privilege escalation and container escape in Google’s kernelCTF. STAR Labs also noted its researchers found the issue “with no help from an AI system.”
Red Hat’s security bulletin confirmed that public exploits are available for CVE-2025-39682 and also confirmed a known exploit exists for CVE-2026-53266. Independent researcher Kimmo Suominen published a technical analysis and a patch‑status tracker for CVE-2026-53266 on GitHub; his write‑up outlines a potential privilege‑escalation path involving modifications to file‑backed memory but notes that the proposed exploitation chain is inferred by analogy with Dirty Pipe and has not been demonstrated with public exploit code.
Operational posture: exploitation, public exploits, and ransomware
CISA’s advisory specifically states the vulnerabilities have been exploited in attacks but provides no operational details on timing, scale, or actors. Separately, the record shows public exploit code is available for at least one of the flaws (CVE-2025-39682), and Red Hat confirms exploit code or known exploits for CVE-2026-53266 as well. CISA’s advisory also notes that, as of its publication, none of the three flaws have been flagged as exploited by ransomware groups.
What this means for federal agencies, security teams, and affected vendors
- Federal agencies: CISA’s order requires agencies to apply available updates and mitigations immediately and to perform forensic triage on every affected asset — a binary deadline accompanied by an explicit audit requirement.
- Security teams and incident responders: teams must prioritize triage on endpoints and infrastructure that use AF_ALG, ebtables SNAT, or kTLS receive paths, and treat the presence of public exploit code as a heightened risk vector for rapid compromise.
- Open‑source and vendor maintainers: published analyses (including Kimmo Suominen’s tracker) and exploit confirmations from Red Hat increase the pressure to backport, patch, and communicate patch status clearly to downstream consumers.
For defenders, the immediate actions are clear in CISA’s language: apply updates and mitigations now, and examine assets for signs of compromise. For investigators and vendors, the open questions CISA left unreported — whom the attackers were, how the exploits were used in the wild, and the scale of successful compromises — remain operationally significant.
The original advisory and reporting are available at: https://www.bleepingcomputer.com/news/security/cisa-alerts-of-active-exploitation-of-three-linux-kernel-flaws/




