Photo by Kevin Horvat on Unsplash. Source: https://unsplash.com/photos/person-in-silhouette-before-computer-code-Pyjp2zmxuLk (Unsplash License).

CISA added three Linux kernel flaws to its Known Exploited Vulnerabilities catalog on 18 September, and the deadline for federal agencies was 21 September.

  • Kernel TLS receive path. A zero-length record skips the record-type check. NVD scores it 9.8 and Red Hat calls it remote when kernel TLS is in use.
  • Bridge ebtables SNAT. The optional ARP sender hardware address rewrite writes out of bounds into a splice-imported page. NVD scores it 8.8 and Red Hat rates it Important.
  • Crypto af_alg socket. Two writers interleave their payloads and leave the socket context inconsistent. NVD scores it 7.8 on the local vector.
  • Red Hat confirmed public exploits against all three on 19 September.

Every pod on a node shares that kernel, so patching means recycling nodes rather than restarting a package. Read the full analysis.

By Ivan Tarin

Ivan Tarin is a Principal Product Marketing Manager at SUSE, where he owns go-to-market strategy and positioning for a seven-product cloud-native portfolio spanning Kubernetes, virtualization, storage, security, and observability. A former full-stack developer who shipped production code for enterprise and public-sector clients including U.S. national laboratories, Ivan translates complex infrastructure and AI technology into messaging that lands with developers, platform teams, and enterprise buyers. He has presented at KubeCon, SUSECON, and AWS Developer Week, and is currently pursuing an MS in Artificial Intelligence at the University of Colorado Boulder.

Leave a Reply

Your email address will not be published. Required fields are marked *

Get the next one before it is old news

Independent analysis of cloud-native infrastructure, Kubernetes and data centre economics. No vendor spin.