CISA added three Linux kernel flaws to its Known Exploited Vulnerabilities catalog on 18 September, and the deadline for federal agencies was 21 September.
- Kernel TLS receive path. A zero-length record skips the record-type check. NVD scores it 9.8 and Red Hat calls it remote when kernel TLS is in use.
- Bridge ebtables SNAT. The optional ARP sender hardware address rewrite writes out of bounds into a splice-imported page. NVD scores it 8.8 and Red Hat rates it Important.
- Crypto af_alg socket. Two writers interleave their payloads and leave the socket context inconsistent. NVD scores it 7.8 on the local vector.
- Red Hat confirmed public exploits against all three on 19 September.
Every pod on a node shares that kernel, so patching means recycling nodes rather than restarting a package. Read the full analysis.
Get the next one before it is old news
Independent analysis of cloud-native infrastructure, Kubernetes and data centre economics. No vendor spin.
