CISA BOD 26-04 Timelines for Three Linux Kernel CVEs

Imported from official source

Cybersecurity Classified by Officially

Executive Summary

CISA added three actively exploited Linux kernel vulnerabilities: CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964 to its KEV Catalog on September 18, 2026, triggering a 3-day remediation deadline that passed on September 21. Under CISA BOD 26-04, a 3-day window applies to CVE-2025-39682 across all assets, and for the other two, the deadline is 3 days for publicly exposed assets and 14 days for internal assets. With the September 21 deadline now passed, affected systems should be patched immediately. Qualys TruRisk Eliminate identifies affected assets with vulnerability context and provides High-Reliability Patches to support remediation and verification.

The Three Linux Kernel CVEs in KEV

Red Hat has updated its advisories for all three to acknowledge active exploitation and reports that public exploits are known. 

Observed exposure across organizations shows these vulnerabilities can affect a substantial number of systems, including internet-facing assets, making timely remediation essential.

CVE-2025-39682 | Linux Kernel TLS Zero-Length Record Vulnerability

A flaw in how the kernel’s TLS receive path handles zero-length records. After zero-copy decryption, a crafted zero-length record can break the logic that assumes the record type cannot change, resulting in memory disclosure or a denial of service. It carries the highest severity of the three.

CVE-2026-53266 | Linux Kernel Netfilter ebtables SNAT Vulnerability

An out-of-bounds write in the bridge Netfilter ebtables SNAT target. A crafted packet with an ARP payload can make the kernel write outside the intended packet buffer, corrupting memory. Depending on the conditions, this can lead to denial-of-service or local privilege escalation.

CVE-2025-39964 | Linux Kernel AF_ALG Socket Race Condition 

This is an extract. The publication continues at the source.

Read the original at the source: https://blog.qualys.com/product-tech/2026/09/23/cisa-bod-26-04-timelines-for-three-linux-kernel-cves

Officially imported this from Qualys’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Qualys — imported from official source
Official source
https://blog.qualys.com/feed RSS
Imported
September 23, 2026 15:00
Versions
1 recorded
Identity
https://blog.qualys.com/?p=42413

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.