CISA's Three Linux Kernel KEV Entries Carry Scores From 7.5 to 9.8, Depending on Who Rates Them
Security / news
CISA's Three Linux Kernel KEV Entries Carry Scores From 7.5 to 9.8, Depending on Who Rates Them
CVE-2026-53266 needs specific bridge rules and local access. CVE-2025-39682 is rated 9.8 by one outlet and Medium by another. The federal deadline was September 21.

A local user on a Linux host that bridges traffic and runs ebtables SNAT rules on ARP can corrupt memory and escalate privileges through CVE-2026-53266, one of three kernel flaws CISA added to its Known Exploited Vulnerabilities catalog in September 2026. The Hacker News dated the addition to September 18 and reported a federal remediation deadline of September 21, a three-day window.
The other two are CVE-2025-39682 in the kernel's TLS receive path and CVE-2025-39964 in the AF_ALG crypto socket interface. Each is a local bug, each has public exploit code or a public demonstration according to the sources below, and none has a named attacker.
CVE-2026-53266: the one with a precondition
The flaw is an out-of-bounds write in the ebtables SNAT ARP rewrite path, which Red Hat's advisory says can "improperly modify underlying memory pages during an ARP sender hardware address rewrite". It needs a bridge netfilter configuration that actually rewrites ARP hardware addresses. A host with no such rules does not reach the vulnerable path, going by Red Hat's description.
Red Hat rates it Important with a CVSS v3 score of 7.5, and says the difference from the 8.8 on cve.org reflects vendor-specific factors and its own products. Its workaround is to disable ARP hardware address rewriting in ebtables SNAT rules, or remove the SNAT rules that act on ARP traffic, until a fixed kernel is installed.
- CVE-2025-39682 (Hacker News)9.8 score
- CVE-2026-53266 (cve.org)8.8 score
- CVE-2025-39964 (Hacker News)7.8 score
- CVE-2026-53266 (Red Hat)7.5 score
Source: The Hacker News (CVE-2025-39682, CVE-2025-39964, cve.org score for CVE-2026-53266) and Red Hat advisory, accessed 2026-09-30
CVE-2025-39682: 9.8 or Medium
The score overstates the risk here, or the label understates it. The Hacker News gave CVE-2025-39682 a CVSS of 9.8 and described it as a TLS receive-path flaw allowing memory disclosure or denial of service for authenticated local users. BleepingComputer called it Medium and described a logic flaw in handling zero-length records that could let different TLS record types be processed together when kernel TLS is in use.
A 9.8 normally means network reachable with no privileges. The Hacker News's own description says authenticated local users, which does not fit that vector. We could not fetch the NVD record in this session, so we cannot say which figure is the published one. Red Hat said there are known public exploits for the flaw it covers, and recommended high priority.

CVE-2025-39964: a 14-year-old race
The AF_ALG race lets concurrent writes corrupt per-socket state. BleepingComputer said the bug existed for 14 years and that STAR Labs researchers publicly demonstrated privilege escalation and container escape with it in Google's kernelCTF. The Hacker News scored it 7.8 and described denial of service or data corruption. BleepingComputer labelled it Critical, which disagrees with that score.
For a host that runs untrusted containers, the container escape is the relevant fact. For a single-tenant server with no untrusted local users, it is a lower priority than the same label implies.
What CISA has and has not said
BleepingComputer said none of the three is flagged in the KEV catalog as used by ransomware groups, and that CISA asked for forensic triage of affected systems. The Hacker News said no details of real-world exploitation methods or attack chains have been disclosed. It also reported that researcher Asim Manizada separately disclosed four further Linux kernel local privilege escalation flaws at around the same time, a claim we found in only that source.
Operators who cannot reboot into a fixed kernel before the federal deadline has passed should apply Red Hat's ebtables mitigation for CVE-2026-53266, and check whether kernel TLS or AF_ALG is used at all. For comparison with another September patch cycle, see our reports on the Zyxel GS1900 switches hit 62 days after the patch and the PeopleSoft WAF bypass.
Sources
More in Security
- 01Fortinet FortiMail Path-Traversal Flaw Exploited Before Fixes ShipCVE-2026-104286 lets an unauthenticated attacker write files to a FortiMail appliance, and one analyst reading of Fortinet's advisory says the patched builds may not be downloadable yet.
- 02Citrix Confirms Two NetScaler Zero-Days Exploited Since Early SeptemberPalo Alto Networks' Unit 42 traces exploitation of CVE-2026-88771 and CVE-2026-88772 to Sept. 4, 23 days before Citrix published its bulletin, and says patching will not evict an attacker who is already inside.
- 03Cisco SD-WAN Manager Auth Bypass Exploited, With No WorkaroundCVE-2026-76504 gives an unauthenticated attacker admin access to the Catalyst SD-WAN Manager API, and Cisco's only advice besides patching is to keep the interface off untrusted networks.
- 04Three Exploited Edge Flaws Test CISA's Three-Day Patch DeadlineCitrix, Cisco and Fortinet appliances landed in the Known Exploited Vulnerabilities catalog within five days, and BOD 26-04 asks agencies to collect evidence before they patch any of them.