Skip to main content

Linux security briefs

14 published alerts for Linux products and services.

Actively exploited (KEV)

CVE-2026-53266

Linux Kernel Out-of-Bounds Write Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-53266). Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. CISA remediation due date: 2026-09-21. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-39964

Linux Kernel Race Condition Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-39964). Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. CISA remediation due date: 2026-09-21. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-39682

Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-39682). Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. CISA remediation due date: 2026-09-21. If you need help checking exposure, call (864) 335-9223.

HighMicrosoft MSRC

CVE-2026-76023

Linux Toolkit Theming vulnerability

Linux Toolkit Theming vulnerability (CVE-2026-76023) was added to Microsoft’s security update guidance. This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-53362

Linux Kernel Unspecified Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-53362). Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux. CISA remediation due date: 2026-08-30. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2022-0995

Linux Kernel Out-of-Bounds Write Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-0995). Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system. CISA remediation due date: 2026-09-09. If you need help checking exposure, call (864) 335-9223.

Microsoft MSRC

CVE-2024-24864

Linux kernel media/dvb-core in dvbdmx_write() vulnerability

Linux kernel media/dvb-core in dvbdmx_write() vulnerability (CVE-2024-24864) was added to Microsoft’s security update guidance. Information published. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2022-0492

Linux Kernel Improper Authentication Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2022-0492). Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature. CISA remediation due date: 2026-06-05. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2026-31431

Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2026-31431). Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation. CISA remediation due date: 2026-05-15. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2018-14634

Linux Kernel Integer Overflow Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2018-14634). Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escalate their privileges on the system. CISA remediation due date: 2026-02-16. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2021-22555

Linux Kernel Heap Out-of-Bounds Write Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2021-22555). Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space. CISA remediation due date: 2025-10-27. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)

CVE-2025-38352

Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-38352). Linux kernel contains a time-of-check time-of-use (TOCTOU) race condition vulnerability that has a high impact on confidentiality, integrity, and availability. CISA remediation due date: 2025-09-25. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2017-1000253

Linux Kernel PIE Stack Buffer Corruption Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2017-1000253). Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges. CISA remediation due date: 2024-09-30. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2024-1086

Linux Kernel Use-After-Free Vulnerability

Linux Kernel is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2024-1086). Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation. CISA remediation due date: 2024-06-20. If you need help checking exposure, call (864) 335-9223.