we_are_coded.by CODE · The world, decoded
БГ
CISA

Three holes in the Linux kernel went onto the exploited list, and their fixes are months old

CISA · event date: 18 September 2026Security

CISA added three kernel vulnerabilities already used in attacks on 18 September, with a deadline of 21 September. Their NVD entries date from September and October 2025 and June 2026. The problem is the machines that never got the fix.

In short
  • CVE-2026-53266 in ebtables, CVE-2025-39964 in AF_ALG and CVE-2025-39682 in kernel TLS.
  • The fixes are in the stable kernel branches CISA points to.
  • For two of the three CISA warns that affected products may be end-of-life.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

The NVD entry for one of the three dates from September 2025. A year later CISA puts it on the list of holes being used in attacks.

Old patch, new attack. The story is about the server nobody updated.

The facts: on 18 September 2026 CISA added three Linux kernel flaws to its catalogue of exploited vulnerabilities, with a deadline for federal agencies of 21 September. CVE-2026-53266 is an out-of-bounds write in the ebtables SNAT target: rewriting the ARP sender hardware address can write directly into a file page imported through splice; its NVD entry dates from June 2026, with a score of 8.8. CVE-2025-39964 is a race condition in AF_ALG, the kernel's interface to cryptography: concurrent writes to the same socket interleave the data and its internal state; its NVD entry dates from October 2025. CVE-2025-39682 is in the kernel's TLS receive path: a zero-length record from the rx_list queue bypasses the record type check; its NVD entry dates from September 2025, with a score of 9.8. The fixes are in the stable kernel branches CISA points to. For two of the three, CISA notes that affected products may be end-of-life and advises moving to a supported version.

Who is really affected

The three are different, and not every one affects everyone. ebtables works in the kernel's network bridges, AF_ALG is its interface to cryptography, and the third is in the kernel's own TLS receive path.

What they share is one thing: all three are fixed in the supported branches. The attack lives where the kernel is frozen - an old distribution, an embedded device, a server that has not been rebooted in years.

An old patch does not protect the machine that never received it.

Check the kernel on your machines with uname -r and compare it with the latest version from your distribution. The NVD entry for the newest of the three dates from June 2026, so a kernel not updated since then is the first to check.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CISA - Known Exploited Vulnerabilities Catalog, entries of 18.09.2026→NVD - CVE-2026-53266→NVD - CVE-2025-39964→NVD - CVE-2025-39682
Original: https://wearecoded.com/en/articles/linux-tri-dupki-v-kataloga-na-cisa.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news