Linux Kernel Flaws Are Being Exploited, Plus 3 Stories
Three Linux kernel flaws are being exploited
Three Linux kernel flaws are now on CISA’s Known Exploited Vulnerabilities list, which is usually the point where a vulnerability stops being an interesting entry in a database and becomes something administrators should actually schedule around.
The three are CVE-2025-39682, CVE-2026-53266 and CVE-2025-39964. CISA’s decision means there is evidence of real-world exploitation. What it does not mean is that every Linux server on the internet suddenly has three identical unauthenticated remote-code-execution holes. In fact, the vendor details are a useful reminder of why a CVE number and one scary score are never the whole story.
CVE-2025-39682 is in the kernel TLS receive path, specifically the handling of a zero-length record. Ubuntu currently rates it Medium priority with a 7.1 CVSS score, while Amazon Linux and Oracle also describe the attack vector as local and require some level of privilege. CVE-2026-53266 lives in netfilter’s ebtables SNAT handling. Red Hat says exploitation requires particular bridge netfilter rules and can lead to memory corruption, denial of service or privilege escalation. CVE-2025-39964 is a race condition in AF_ALG, the kernel interface that lets user-space programs use Linux cryptographic algorithms; Red Hat says a local low-privilege user can crash the system or corrupt cryptographic-operation results.
So, yes, patch. But don’t turn “three Linux kernel vulnerabilities” into “all Linux is remotely owned.” CISA hasn’t publicly identified the attackers, victims or the way these flaws are being used, and the affectedness of a particular server depends on the distribution, kernel build, configuration and fixes the vendor has backported.
That last part matters. Linux distributions routinely patch an older-looking kernel without changing it to the newest upstream version number. Your scanner can say “vulnerable” while your distribution says the exact package is fixed, or the reverse if the scanner’s data is stale. Check the advisory for the Linux distribution you actually run, install the vendor-supplied fixed kernel, reboot into it when required, and verify which kernel is running afterward. If you operate hosting, shared systems or other machines where untrusted users can obtain a foothold, I’d give these more urgency and preserve enough logs to investigate suspicious privilege changes or crashes.
The boring answer is still the good answer: know what you run, patch what applies, and verify the machine actually came back on the fixed kernel. Boring is underrated.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
TikTok’s $400 million privacy deal isn’t settled yet
TikTok and ByteDance’s proposed $400 million U.S. child-privacy settlement looked, at first glance, like a very large period at the end of a very long sentence. A federal judge is now signaling that at least one part of that period may need an eraser.
The agreement would resolve Justice Department claims that TikTok and predecessor Musical.ly violated the Children’s Online Privacy Protection Act by collecting personal information from children under 13 without the required parental consent. TikTok would pay $300 million immediately, with another $100 million tied to ending a 2019 Federal Trade Commission consent decree.
U.S. District Judge George H. Wu has indicated that he is not yet convinced the older decree should be terminated. According to Reuters, the court said the proposal did not give enough detail to show that ending the decree would provide a durable remedy. That 2019 order includes privacy-compliance reporting requirements that currently run through 2029. A hearing is scheduled for Monday.
This is preliminary. The judge has not rejected the entire $400 million settlement, and the allegations being settled are not a judicial finding that every claim is true. But it is a useful correction to the headline version of a big regulatory settlement: the money is only part of the remedy. The court also wants to know what behavior changes, how those changes are monitored and what happens after everybody stops issuing press releases about the number.
For parents and ordinary TikTok users, there is no new setting to change this morning. The larger issue is whether age gates, parental-consent systems and under-13 protections work in practice rather than merely existing in a policy document.
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
A federal appeals court wants humans to verify AI filings
The Tenth U.S. Circuit Court of Appeals has proposed a rule that would require a human to independently verify court filings prepared with the help of generative AI. That sounds obvious. Recent court history suggests it apparently needs to be written down.
Under the proposal, lawyers and self-represented litigants would certify that a human reviewed an AI-assisted filing before submission and independently verified every cited authority, quotation, citation and piece of legal analysis, along with compliance with court rules and ethical obligations. The court could strike a filing, impose monetary sanctions, dismiss or affirm an appeal, or begin disciplinary proceedings when the rule is violated.
If adopted, Reuters says it would be the first rule of its kind among the 13 federal appeals courts. The Tenth Circuit covers Colorado, Kansas, New Mexico, Oklahoma, Utah and Wyoming. Public comments run through October 18, with a final decision expected by December 1 and an effective date of January 1, 2027.
Raymond Tec covered a particularly ugly example of the problem last week, when New Mexico’s Supreme Court sanctioned an attorney $5,000 after an AI-assisted filing included invented witnesses, fabricated testimony and false legal authority. The lesson here is not “lawyers shouldn’t use AI.” AI can summarize, organize, compare and draft very effectively. The problem begins when the draft becomes the source of truth.
The proposed rule applies to court filings, not every profession. Still, I like the operating principle a lot: AI can do work; it cannot inherit your accountability for that work. If your name goes on the result, verification is still your job.
Turning on AI is the easy part
Deciding what an AI tool should be allowed to see, who should use it, what work it should perform, and what happens when it gets something wrong is the more interesting problem. Raymond Tec helps businesses connect and automate the tools they actually use without treating every new feature like a button that obviously needs to be switched on.
China’s CXMT says new DRAM production is underway
And finally, something that may eventually help with the unpleasant hardware-price story we’ve been following.
Chinese memory maker CXMT says its fifth-generation DRAM manufacturing platform has entered mass production. DRAM is the working memory your computer or phone uses while programs are running, and it is one of the components that has been under increasingly ugly supply pressure as AI infrastructure absorbs enormous amounts of memory capacity.
CXMT also announced two 24-gigabit LPDDR5X mobile-memory products. The company says they store 50% more data than its previous comparable products and that the new manufacturing process can produce at least 50% more gross chip dies from a silicon wafer than its fourth-generation process.
“Gross” is doing useful work in that sentence. It counts the potential chips cut from a wafer before defective ones are removed. Actual yield — how many chips pass testing — still matters enormously. CXMT also says its process capability is now comparable to the most advanced mass-produced memory nodes. That is the company’s claim, not an independently demonstrated industry ranking.
The interesting technical trick is quadruple patterning. Instead of relying on a single lithography step to draw an extremely fine circuit pattern, the manufacturer repeats patterning steps so it can create smaller features with the equipment it has available. CXMT says it has reduced key feature spacing to 11.95 nanometers despite U.S. restrictions that limit China’s access to some advanced chipmaking tools.
Does this fix the memory shortage? No. One manufacturer’s new production platform doesn’t instantly change global supply, yields, customer qualification, trade restrictions or the amount of high-end memory being swallowed by AI data centers. But more capable production from another supplier is directionally good news. If the process performs at scale the way CXMT says it does, it adds supply pressure in a market that badly needs some.
Earlier this month I wrote that businesses shouldn’t assume next year’s equivalent laptop will automatically be cheaper. I still wouldn’t. But this is at least one development pointing toward more production rather than another story about somebody reserving everything that already exists.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- CISA Known Exploited Vulnerabilities Catalog
- Red Hat: CVE-2026-53266
- Red Hat: CVE-2025-39964
- Ubuntu: CVE-2025-39682
- Reuters: U.S. judge signals rejection of part of TikTok privacy settlement
- U.S. Justice Department: TikTok and ByteDance privacy settlement
- Reuters: U.S. appeals court rule would require AI-filing certification
- Tenth Circuit proposed 2027 rules
- Reuters: CXMT says fifth-generation DRAM platform enters mass production
