High CVE-2025-39682, CVE-2026-53266, CVE-2026-53362, CVE-2025-39964, CVE-2022-0995, CVE-2022-0492 — CISA flagged six Linux kernel vulnerabilities as actively exploited in August and September 2026, from a 9.8 kernel-TLS bug to old container escapes. What each does and the Debian, Ubuntu and Proxmox kernels that fix them.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: Six Linux kernel bugs, some brand new and some from 2022, are now confirmed exploited. Most let a local user or container get root; one (kernel TLS, CVSS 9.8) is reachable over the network on systems that use kTLS. The fix for all of them is the same: install your distro's current kernel and reboot into it. Long-uptime servers on old kernels are the ones at risk.
| CVE-2025-39682 | Kernel TLS (kTLS) zero-length record handling. CVSS 9.8. Kernels 6.0+ |
|---|---|
| CVE-2026-53266 | ebtables SNAT ARP rewrite (bridge netfilter). CVSS 8.8. Kernels 5.10+ |
| CVE-2026-53362 | IPv6 fragmentation overflow. CVSS 7.8. Kernels 6.0+ |
| CVE-2025-39964 | AF_ALG concurrent writes (crypto socket). CVSS 7.8. Kernels 2.6.38+ |
| CVE-2022-0995 | watch_queue out-of-bounds write → local root. Fixed in 5.17 (2022) |
| CVE-2022-0492 | cgroups v1 release_agent → container escape. Fixed in 5.17 (2022) |
| Exploited? | Yes, all on CISA KEV between 2026-06-02 and 2026-09-18 |
| CVE | Where | What it gives an attacker | KEV added |
|---|---|---|---|
| CVE-2025-39682 | Kernel TLS receive path | Memory corruption when a TLS 1.3 socket processes a zero-length record. Rated 9.8 (network). Only matters where kTLS is in use (some nginx/HAProxy/OpenSSL builds enable it). | 2026-09-18 |
| CVE-2026-53266 | ebtables SNAT (bridge firewall) | Writes to a shared packet buffer when rewriting ARP. Relevant to hosts that bridge traffic: hypervisors, container hosts. | 2026-09-18 |
| CVE-2025-39964 | AF_ALG crypto socket | Concurrent writes corrupt socket state → local privilege escalation. Same interface as Copy Fail. | 2026-09-18 |
| CVE-2026-53362 | IPv6 fragmentation | Buffer overflow when building fragmented IPv6 packets → local root. | 2026-08-27 |
| CVE-2022-0995 | watch_queue notifications | Out-of-bounds write → local root. Public exploit since 2022. | 2026-08-26 |
| CVE-2022-0492 | cgroups v1 release_agent | Escape from a container to the host under certain configurations. | 2026-06-02 |
The two 2022 bugs being added now tells you something: attackers are finding plenty of servers and appliances that haven’t had a kernel update in four years.
uname -r # the kernel you're RUNNING
needrestart -k 2>/dev/null # Debian/Ubuntu: is a newer kernel installed but not booted?
ls /var/run/reboot-required 2>/dev/null && echo "reboot pending"
Minimum fixed kernels on Debian:
| CVE | Debian 12 (6.1) | Debian 13 (6.12) |
|---|---|---|
| CVE-2025-39682 | 6.1.153-1 | 6.12.48-1 |
| CVE-2025-39964 | 6.1.158-1 | 6.12.57-1 |
| CVE-2026-53266 | 6.1.176-1 | 6.12.94-1 |
| CVE-2026-53362 | 6.1.177-1 | 6.12.95-1 |
So on Debian 12 you want 6.1.177-1 or later; on Debian 13, 6.12.95-1 or later. Ubuntu, RHEL and others: install the latest kernel update and check your vendor’s tracker for each CVE. Upstream stable fixes landed in 6.1.177, 6.6.144, 6.12.95 and 6.18.38 for the newest of the four.
Proxmox VE: Proxmox backports upstream CVE fixes into its own kernel builds. Run apt full-upgrade to get the newest proxmox-kernel and reboot; On Proxmox VE 8 the changelog lists CVE-2026-53362 as fixed in proxmox-kernel-6.8.12-35 (2026-07-14); the others are included in the rolled-up upstream backports, so simply run the newest build.
# Debian / Ubuntu / Proxmox
apt update && apt full-upgrade
reboot
uname -r
# RHEL / Rocky / Alma / Fedora
dnf upgrade --refresh 'kernel*'
reboot
The reboot is the part that gets skipped. A server with 300 days of uptime is running a 300-day-old kernel no matter how many updates are installed on disk.
echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif-aead.conf; rmmod algif_aeadrelease_agent path.--privileged or CAP_SYS_ADMIN.Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.