By Interestana AI Editorial — AI-drafted, human-overseen. How we report
CISA Adds Three Exploited Linux Kernel Flaws to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced on Friday, October 25, 2024, the addition of three security vulnerabilities affecting the Linux kernel to its catalog of Known Exploited Vulnerabilities (KEV). This designation signifies that CISA has credible evidence of these flaws being actively exploited in the wild, posing an immediate threat to U.S. federal agencies and other organizations. The inclusion in the KEV catalog mandates that federal agencies must patch these vulnerabilities within specific timeframes to mitigate risks.
The three vulnerabilities identified are CVE-2025-39682, CVE-2024-45861, and CVE-2024-1086. CVE-2025-39682 is described as an "improper check for unusual or exceptional conditions vulnerability" within the Transport Layer Security (TLS) receive path. This flaw carries a critical CVSS (Common Vulnerability Scoring System) score of 9.8, indicating a severe level of risk. The TLS protocol is fundamental for establishing secure communication channels over networks, and a vulnerability in its receive path could potentially allow attackers to disrupt or compromise secure connections. The specific nature of the "improper check" suggests a failure in validating certain conditions or inputs, which could lead to unexpected behavior or system compromise.
CVE-2024-45861 is characterized as a "use-after-free" vulnerability. This type of vulnerability occurs when a program attempts to access memory that has already been freed, leading to unpredictable behavior, crashes, or potentially allowing an attacker to execute arbitrary code. The specific component or function within the Linux kernel where this use-after-free occurs is not detailed in the initial announcement but is a common vector for exploitation. Similarly, CVE-2024-1086 is also identified as a use-after-free vulnerability, further emphasizing the critical nature of memory management in the Linux kernel and the potential for attackers to leverage these errors for malicious purposes.
The inclusion of these vulnerabilities in the KEV catalog underscores the ongoing efforts by CISA to identify and track actively exploited threats. The agency's directive requires federal civilian executive branch agencies to implement security measures to protect their networks against these specific threats. Organizations utilizing the Linux operating system, which powers a vast array of servers, cloud infrastructure, and embedded devices, are strongly advised to review their systems and apply necessary patches and mitigations promptly. The active exploitation of these flaws means that unpatched systems are already at risk of compromise, necessitating urgent attention from system administrators and cybersecurity professionals.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.