The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a new high-severity vulnerability in the Linux to its list of Known Exploitable Vulnerabilities (KEV), signaling that it is being actively exploited in attacks. The warning, issued on September 4, 2025, calls for immediate action by federal agencies and private sector organizations to address the threat.
See also: CISA adds two TP-Link vulnerabilities to the KEV List

The vulnerability, codenamed CVE-2025-38352, is a Time-of-Check Time-of-Use (TOCTOU) Race Condition. This type of vulnerability creates a small window of opportunity for an attacker to maliciously change a system resource between the time the system checks its security state and the time it actually uses that resource. A successful exploitation could allow an attacker to gain elevated privileges, manipulate sensitive data , or cause a system crash, leading to a high impact on confidentiality, integrity, and availability.
In response to the confirmed “in-the-wild” exploit, the addition of CISA to the KEV list triggers a binding operational directive for federal agencies. Under Binding Operational Directive (BOD) 22-01, Federal Citizens Executive Branch (FCEB) agencies are required to implement the mitigations provided by the vendors or discontinue use of the product by the September 25, 2025 deadline.
See also: CISA: Warns of critical vulnerability in SunPower devices

While the guidance is mandatory for federal agencies, CISA strongly urges all organizations to prioritize patching this vulnerability due to the widespread use of the Linux kernel. Linux serves as the foundation for a wide range of systems, including web servers, cloud infrastructure, Android devices, and Internet of Things (IoT) devices, making the potential attack surface vast.
“A vulnerability in the Linux kernel is a fundamental risk that can affect countless technologies around the world,” a security analyst noted. At this time, it is not known whether this vulnerability is being used in specific ransomware campaigns. However, attackers often use such kernel-level exploits to gain deeper access and persistence within a network before deploying ransomware or extracting data.
See also: CISA: New TP-Link and WhatsApp vulnerabilities in the KEV Catalog

CISA recommends applying patches and mitigations from Linux distribution vendors as soon as they become available. If mitigations are not available for a specific product, organizations should follow the relevant cloud service or discontinue use of the product to remove the threat. System administrators are advised to contact the specific Linux distribution vendors, such as Red Hat, Canonical (Ubuntu), and SUSE, for security updates and remediation instructions.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
