CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
High · The Hacker News ·
CISA KEV · Exploited
What happened
CISA added three Linux kernel flaws to KEV, including CVE-2025-39682 (CVSS 9.8) in TLS receive path, with active exploitation. Linux systems are affected.
What to do now
Apply Linux kernel security updates from your distro vendor now; prioritize internet-facing/TLS servers. Verify all three CVEs with vendor advisory. If kTLS is unused, disable it; monitor for exploitation.
CVE references
- CVE-2025-39682
Original source
AI-assisted analysis, sources cited. Verify with the vendor advisory before acting.