LIVE · cybersecurity feed
Live wire
vulnerabilitycritical

CISA alerts of active exploitation of three Linux kernel flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of three distinct vulnerabilities within the Linux kernel, one of which is rated critical. These security issues were added to CISA's catalog last week, with severity ratings ranging from medium to critical. Federal agencies have been mandated to apply available security…

ZeroDay News ·

Source: BleepingComputer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding the active exploitation of three distinct vulnerabilities within the Linux kernel, one of which is rated critical. These security issues were added to CISA's catalog last week, with severity ratings ranging from medium to critical. Federal agencies have been mandated to apply available security updates and mitigations for these flaws by the end of today.

One of the vulnerabilities, identified as CVE-2025-39964, is a race condition found in the kernel's AF_ALG cryptographic socket interface. This flaw, which has existed in the Linux kernel for 14 years, allows concurrent writes to corrupt per-socket state, potentially leading to system crashes or alterations of cryptographic results. Offensive security company STAR Labs discovered this issue, demonstrating its potential for privilege escalation and container escape within Google's kernelCTF environment.

Another critical vulnerability is CVE-2026-53266, an out-of-bounds write flaw in the Linux kernel's ebtables SNAT implementation. This defect can cause an ARP address rewrite to modify shared file-backed memory without first ensuring the affected packet range is writable. Red Hat has confirmed the existence of a known exploit for this vulnerability. Researcher Kimmo Suominen has published a technical analysis and patch-status tracker on GitHub, outlining a potential privilege-escalation path, though this specific exploitation chain is inferred by analogy with the "Dirty Pipe" vulnerability and has not been publicly demonstrated.

The third vulnerability, CVE-2025-39682, is a logic flaw in the Linux kernel's TLS receive-path. It mishandles zero-length records queued for later processing, which could allow different TLS record types to be processed together when kTLS is in use. Public exploits for this flaw are available, a fact also confirmed by Red Hat in its security bulletin.

CISA has confirmed that all three vulnerabilities are actively being exploited in attacks, though the agency has not provided specific details about the incidents or the nature of the threat actors involved. The agency has marked all three flaws as requiring forensic triage, meaning federal agencies must examine affected assets for any signs of prior exploitation. As of now, none of these vulnerabilities are flagged as being exploited by ransomware groups.

vulnerabilitycloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Intent injection attacks are a new worry for AI-native 6G networks

Researchers from the University of Ottawa and Nokia Bell Labs have identified a new class of threat, termed adversarial intent injection, targeting AI-native 6G networks that utilize intent-based networking (IBN). This attack vector exploits the abstraction inherent in IBN systems, where operators define desired outcomes and software translates these into network policies. The researchers…

vulnerability

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating that federal civilian executive branch (FCEB) agencies address these flaws by September 21, 2026. This directive, issued under Binding Operational Directive (BOD) 22-01, aims to mitigate significant risks posed by actively…

security

Google Fined €403 Million Over Location Data Practices

Ireland’s Data Protection Commission (DPC) has imposed a fine of €403 million on Google for violations of the General Data Protection Regulation (GDPR) related to its handling of user location data. The decision, announced on September 21, 2026, concludes an investigation initiated in February 2020, which itself stemmed from complaints filed by several European consumer groups, including BEUC,…

security

ShinyHunters Hacked Clop. Now What About Clop's Victims?

A recent report indicates that the ShinyHunters threat group has successfully compromised the dark web infrastructure associated with the Clop ransomware operation. This incident reportedly involved the defacement of Clop's dark web site and a claim by ShinyHunters to have exfiltrated data pertaining to Clop's victims. The primary concern arising from this alleged breach is the potential for…

nation-state

Gopass: Open-source command-line password manager for teams

Gopass, an open-source command-line password manager designed for teams, stores credentials in an encrypted format and operates without requiring a network connection, making it suitable for air-gapped systems. The tool functions as a direct replacement for the traditional Unix password manager, `pass`.

ai

AI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factor

Forty percent of large companies have experienced an AI-related compliance or governance issue within the last year, according to a survey of 1,000 senior IT, operations, and transformation leaders. Process-related problems were cited as a contributing factor in 84% of these incidents.