What Happened
CISA added CVE-2025-39682, an improper-condition-check flaw in the Linux kernel’s TLS receive path carrying a CVSS score of 9.8, to its Known Exploited Vulnerabilities catalog, joining two flaws already listed: CVE-2026-53266, an out-of-bounds write in the ebtables SNAT ARP rewrite path with a CVSS score of 8.8, and CVE-2025-39964, a race condition in AF_ALG socket handling with a CVSS score of 7.8. All three carry confirmed evidence of active exploitation, and the trio spans unrelated kernel subsystems, pointing to a broad campaign against Linux systems rather than a single exploit chain. Under Binding Operational Directive 26-04, federal civilian agencies face a remediation deadline of September 21 and are ordered to conduct forensic triage on exposed assets, treating patch installation as the starting point for a response rather than the end of it. Read more from The Hacker News.
Why This Matters for Canadian Organizations
Canadian federal departments, provincial agencies, and much of the country’s cloud and hosting infrastructure run on Linux, and the Canadian Centre for Cyber Security has repeatedly flagged kernel-level vulnerabilities as a priority patching category in its own guidance. Financial institutions overseen by OSFI Guideline B-13 and organizations subject to PIPEDA breach-notification duties face the same underlying exposure as their US counterparts, since local privilege-escalation flaws in the kernel give an attacker who already has a foothold the ability to move from a low-privilege account to full system control. Canada has no domestic directive mirroring BOD 26-04’s forensic-triage requirement, leaving the decision to investigate rather than simply patch up to individual security teams, a gap worth closing given the active exploitation already confirmed south of the border.
What to Do
Security teams running Linux systems, particularly internet-facing servers and anything handling TLS traffic, ebtables-based network address translation, or kernel cryptographic sockets, should apply current kernel patches without delay. Teams should also review logs and system state for signs of compromise predating the patch, not only confirm the patch installed, since CISA’s forensic-triage requirement reflects an assessment these flaws have already been used against real targets. Organizations without a Linux patch cadence tied to KEV catalog updates should consider building one, given how frequently kernel flaws are landing on the list this year.






