The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting three Linux kernel vulnerabilities, with severity ratings ranging from medium to critical.
One flaw, CVE-2025-39964, existed in the Linux kernel for 14 years. CISA added all three issues to its highest-priority list for federal agencies and ordered them to apply available security updates and mitigations by the end of today. CISA said the vulnerabilities have been exploited in attacks but provided no details about the incidents or the threat actors.
Offensive security company STAR Labs found CVE-2025-39964. Its researchers demonstrated privilege escalation and container escape in Google’s kernelCTF, without help from an AI system.
Public exploits are available for CVE-2025-39682, according to Red Hat. Red Hat also confirmed a known exploit for CVE-2026-53266. Researcher Kimmo Suominen published a GitHub analysis and patch-status tracker describing a possible privilege-escalation path involving file-backed memory, but said the chain is inferred by analogy with Dirty Pipe and has not been demonstrated with public exploit code.
CISA marked all three flaws for “forensic triage,” requiring federal agencies to check affected assets for signs of prior exploitation. None is currently flagged as exploited by ransomware groups.
Comments
0No comments yet. Be the first to comment.