CVE-2025-39682
Sfruttamento noto · CISA KEV
CVSS 7.1 HIGH: in the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the… EPSS 1% (67º percentile).
Data di correzione federale CISA 21 set
Vulnerabilità · 8 ore fa
CISA ha aggiunto tre vulnerabilità del Linux kernel al catalogo KEV e ha imposto alle agenzie federali la patch entro tre giorni. Per chi gestisce server, nodi Kubernetes o host condivisi, il punto non è una singola app esposta: il kernel sta sotto tutto il resto, quindi il raggio d’azione è l’intera macchina.
Una delle tre falle può portare a DoS o disclosure di memoria quando il kernel sbaglia a gestire un record a lunghezza zero nel percorso TLS. Un’altra è una race condition su AF_ALG: due scritture concorrenti sullo stesso socket possono mescolare i dati e mandare in crash il sistema o alterare il risultato crittografico. La terza è una out-of-bounds write nel target SNAT di ebtables: un pacchetto ARP costruito ad arte può corrompere memoria fuori dal buffer previsto.
Per ambienti Linux condivisi, questa è una correzione da trattare come urgente a livello host, non come normale ciclo applicativo. Finché resta in giro un kernel vulnerabile, ogni workload che lo condivide eredita la stessa esposizione.
Sfruttamento noto · CISA KEV
CVSS 7.1 HIGH: in the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the… EPSS 1% (67º percentile).
Data di correzione federale CISA 21 set
Sfruttamento noto · CISA KEV
CVSS 3.3 LOW: in the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in… EPSS 0.8% (55º percentile).
Data di correzione federale CISA 21 set
Sfruttamento noto · CISA KEV
CVSS 8.8 HIGH: in the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite… EPSS 0.3% (20º percentile).
Data di correzione federale CISA 21 set
3 fonti che coprono questa storia
CISA alerts of active exploitation of three Linux kernel flaws
Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical.
Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities
Attackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory.
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
Public exploits for four patched Linux kernel flaws let local users gain root; three require unprivileged user namespaces.
Part of the PlainSec briefing for 2026-09-21