Desert Forge IT — Arizona IT · Field-tested tools & guidesFree consult →

6 Linux Kernel CVEs Added to CISA's Exploited List (Aug-Sep 2026): CVE-2025-39682, 2026-53266, 2026-53362 & More

High CVE-2025-39682, CVE-2026-53266, CVE-2026-53362, CVE-2025-39964, CVE-2022-0995, CVE-2022-0492 — CISA flagged six Linux kernel vulnerabilities as actively exploited in August and September 2026, from a 9.8 kernel-TLS bug to old container escapes. What each does and the Debian, Ubuntu and Proxmox kernels that fix them.

Published 2026-10-08 · Last updated 2026-10-08

TL;DR: Six Linux kernel bugs, some brand new and some from 2022, are now confirmed exploited. Most let a local user or container get root; one (kernel TLS, CVSS 9.8) is reachable over the network on systems that use kTLS. The fix for all of them is the same: install your distro's current kernel and reboot into it. Long-uptime servers on old kernels are the ones at risk.

CVE-2025-39682Kernel TLS (kTLS) zero-length record handling. CVSS 9.8. Kernels 6.0+
CVE-2026-53266ebtables SNAT ARP rewrite (bridge netfilter). CVSS 8.8. Kernels 5.10+
CVE-2026-53362IPv6 fragmentation overflow. CVSS 7.8. Kernels 6.0+
CVE-2025-39964AF_ALG concurrent writes (crypto socket). CVSS 7.8. Kernels 2.6.38+
CVE-2022-0995watch_queue out-of-bounds write → local root. Fixed in 5.17 (2022)
CVE-2022-0492cgroups v1 release_agent → container escape. Fixed in 5.17 (2022)
Exploited?Yes, all on CISA KEV between 2026-06-02 and 2026-09-18

The six bugs

CVEWhereWhat it gives an attackerKEV added
CVE-2025-39682Kernel TLS receive pathMemory corruption when a TLS 1.3 socket processes a zero-length record. Rated 9.8 (network). Only matters where kTLS is in use (some nginx/HAProxy/OpenSSL builds enable it).2026-09-18
CVE-2026-53266ebtables SNAT (bridge firewall)Writes to a shared packet buffer when rewriting ARP. Relevant to hosts that bridge traffic: hypervisors, container hosts.2026-09-18
CVE-2025-39964AF_ALG crypto socketConcurrent writes corrupt socket state → local privilege escalation. Same interface as Copy Fail.2026-09-18
CVE-2026-53362IPv6 fragmentationBuffer overflow when building fragmented IPv6 packets → local root.2026-08-27
CVE-2022-0995watch_queue notificationsOut-of-bounds write → local root. Public exploit since 2022.2026-08-26
CVE-2022-0492cgroups v1 release_agentEscape from a container to the host under certain configurations.2026-06-02

The two 2022 bugs being added now tells you something: attackers are finding plenty of servers and appliances that haven’t had a kernel update in four years.

Am I affected?

uname -r                    # the kernel you're RUNNING
needrestart -k 2>/dev/null  # Debian/Ubuntu: is a newer kernel installed but not booted?
ls /var/run/reboot-required 2>/dev/null && echo "reboot pending"

Minimum fixed kernels on Debian:

CVEDebian 12 (6.1)Debian 13 (6.12)
CVE-2025-396826.1.153-16.12.48-1
CVE-2025-399646.1.158-16.12.57-1
CVE-2026-532666.1.176-16.12.94-1
CVE-2026-533626.1.177-16.12.95-1

So on Debian 12 you want 6.1.177-1 or later; on Debian 13, 6.12.95-1 or later. Ubuntu, RHEL and others: install the latest kernel update and check your vendor’s tracker for each CVE. Upstream stable fixes landed in 6.1.177, 6.6.144, 6.12.95 and 6.18.38 for the newest of the four.

Proxmox VE: Proxmox backports upstream CVE fixes into its own kernel builds. Run apt full-upgrade to get the newest proxmox-kernel and reboot; On Proxmox VE 8 the changelog lists CVE-2026-53362 as fixed in proxmox-kernel-6.8.12-35 (2026-07-14); the others are included in the rolled-up upstream backports, so simply run the newest build.

How to patch

# Debian / Ubuntu / Proxmox
apt update && apt full-upgrade
reboot
uname -r

# RHEL / Rocky / Alma / Fedora
dnf upgrade --refresh 'kernel*'
reboot

The reboot is the part that gets skipped. A server with 300 days of uptime is running a 300-day-old kernel no matter how many updates are installed on disk.

Mitigations until you can reboot

  • Block the AF_ALG AEAD module, which also closes Copy Fail: echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif-aead.conf; rmmod algif_aead
  • Use cgroups v2 (the default on current Debian, Ubuntu and Proxmox). CVE-2022-0492 only affects the v1 release_agent path.
  • Run untrusted containers unprivileged and with the default seccomp/AppArmor profiles. Never run them with --privileged or CAP_SYS_ADMIN.
  • If you don’t use bridged ebtables rules, you aren’t exercising CVE-2026-53266, but don’t rely on that; virtualisation hosts often load ebtables implicitly.

Sources

← Back to Knowledge Base

Want this handled for you?

Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.

Get a free security check →  ·  More security advisories