Patch Analysis & Exploitation Timeline: Same-Week KEV Additions, Year-Apart Patch Dates - Linux Kernel, September 18, 2026
Three Linux kernel vulnerabilities entered CISA’s KEV catalog on September 18, 2026, although their Linux 6.12 fixes were available 91–386 days earlier. This analysis separates patch availability, CVE publication, and known-exploitation status without treating KEV dates as first-attack dates.
Patch Analysis & Exploitation Timeline: Linux 6.12 Fixes Preceded Three KEV Listings by 91–386 Days
Dataset Summary
| Field | Value | Interpretation |
|---|---|---|
| Reporting Period | September 18, 2026 KEV additions | The selected timelines extend from August 28, 2025 to September 18, 2026. Catalog due dates are September 21, 2026; source review was completed September 28, 2026. |
| Data Sources | Supplied CVE list; CISA KEV; CVE Program and NVD records; official Linux release history | The supplied list defines the scope. Public primary sources establish the additional publication, release, and technical details. |
| Total CVEs Analyzed | Three | CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682, all affecting the Linux kernel. |
| Reference Patch Branch | Upstream Linux 6.12.x | One common branch keeps the release comparison consistent. These dates are not the earliest fixes across every branch or distribution. |
| Average CVE-Publication-to-Reference-Patch Gap | −10.67 calendar days | The selected fixed releases preceded formal CVE publication. This is not a measurement from the earliest public disclosure. |
| Average / Median Reference-Patch-to-KEV Gap | 278.33 days / 358 days | Calculated from 91, 358, and 386 calendar days. These intervals measure release-to-catalog timing, not attacker activity. |
| Shortest / Longest Reference-Patch-to-KEV Gap | 91 days / 386 days | CVE-2026-53266 has the shortest interval; CVE-2025-39682 has the longest. |
| Average Patch-to-First-Exploitation Gap | Unavailable | No exact first-exploitation date is established for any of the three CVEs in the reviewed sources. |
| KEV-to-Due-Date Interval | Three calendar days for all three | September 18 to September 21, 2026. A catalog deadline is not an attacker-free period. |
Sourcing and Methodology Note
The supplied three-entry list sets the scope. The CISA Known Exploited Vulnerabilities Catalog, snapshot 2026.09.27, corroborates the addition dates, due dates, weakness classifications, and triage fields. The CVE Program records for CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682, together with their corresponding NVD records (39964, 53266, 39682), provide the publication, CVSS, and technical context.
Patch dates come from the official Linux release history and ChangeLog-6.12.44 (August 28, 2025), ChangeLog-6.12.49 (September 25, 2025), and ChangeLog-6.12.94 (June 19, 2026). Each changelog contains the correction linked by its CVE record. The calculations below are this article’s analytical layer, not statistics published by CISA.
Operational context is drawn from BOD 26-04, Prioritizing Security Updates Based on Risk, its implementation guidance, the Linux Kernel TLS documentation, and the published Red Hat explanation What is backporting and how does it affect Red Hat Enterprise Linux? Product capabilities in the closing section follow the official Saner Patch Management page. Unconfirmed dates remain unavailable.
Introduction
The Linux 6.12 fixes for these three vulnerabilities were available 91 to 386 days before their September 18, 2026 KEV listings. The mean interval is 278.33 days, while the median is 358 days. Two of the selected fixes were released in 2025; the third followed in June 2026.
The finding is a separation between patch availability and catalog inclusion, not a reconstruction of when attackers first acted. For defenders, it illustrates why a newly added KEV may require a fresh assessment of an older vulnerability and its already-published fix.
Background and Context
The cohort spans three different kernel paths: concurrent writing through AF_ALG, an ARP address rewrite in the ebtables SNAT target, and record handling in the kernel TLS receive path. Their common catalog date does not establish a common attack chain, identical prerequisites, or a shared campaign.
Linux fixes can appear in several maintained branches, and distributions can backport corrections into packages with older upstream version numbers. The analysis therefore uses the first fixed upstream 6.12.x release named in each CVE record as a consistent reference. It does not treat that release date as the date every downstream product received an update.
Formal CVE publication also differs from public code availability. Here, all three reference fixes predate their CVE publications. Calling those publication dates the first disclosure of every technical detail would erase information already present in the release history.
Gap Calculation Methodology
D is the calendar date in the CVE record’s datePublished field. P is the release date of the selected fixed Linux 6.12.x version. K is CISA’s dateAdded, E is the actual first-exploitation date, and R is the catalog due date.
CVE-publication-to-reference-patch gap = P − D
Reference-patch-to-KEV gap = K − P
Reference-patch-to-first-exploitation gap = E − P
Catalog remediation interval = R − K
Differences use calendar days without inclusive counting. A patch author’s timestamp is not substituted for the release date. Negative P − D values mean the fixed release preceded formal CVE publication; they do not describe negative remediation time.
KEV inclusion is used only as a dated catalog milestone confirming known exploitation. It is not substituted for E, and it does not quantify “mass exploitation.” The reviewed records do not establish a common measure of attack scale or exact first-attack dates. All three CVEs remain in the release-to-KEV calculation; none supports an exact E-based interval.
Patch Timeline & Exploitation Gap Analysis
The reference-patch-to-KEV distribution is [91, 358, 386] calendar days. Its mean is 278.33 days and its median is 358 days. The 91-day observation pulls the mean below the median, so reporting the mean alone would obscure the two longer intervals.
| Metric | Mean | Median | Coverage and Meaning |
|---|---|---|---|
| CVE publication → reference patch | −10.67 days | −8 days | Three observations: −18, −6, and −8 days. All selected releases predate formal CVE publication. |
| Reference patch → KEV addition | 278.33 days | 358 days | All three CVEs; this is the article’s primary timing measure. |
| Reference patch → actual first exploitation | Unavailable | Unavailable | No exact first-exploitation dates are established. |
| KEV addition → catalog due date | 3 days | 3 days | All three entries share the same catalog dates. |
CVSS severity-band comparison. To keep the scoring source consistent, this comparison uses the Linux CNA’s CVSS v3.1 values in the CVE Program records: CVE-2025-39964 is 7.8 High, CVE-2026-53266 is 8.8 High, and CVE-2025-39682 is 9.8 Critical.
| CVSS Severity Band | CVEs | Reference-Patch-to-KEV Gaps | Mean / Median | Interpretation |
|---|---|---|---|---|
| High | CVE-2025-39964 (7.8); CVE-2026-53266 (8.8) | 358 days; 91 days | 224.5 / 224.5 days | Two observations with a 267-day spread; they do not form a consistent severity-specific timing pattern. |
| Critical | CVE-2025-39682 (9.8) | 386 days | 386 / 386 days | One observation only; it cannot establish a Critical-band trend. |
The single Critical-severity case has a longer reference-patch-to-KEV interval than either High-severity case, but the cohort is too small to conclude that CVSS severity meaningfully explains the gap. The severity comparison is therefore descriptive, not a severity-to-timing correlation.
These figures do not measure enterprise patch deployment or the time CISA took to act after receiving evidence. Neither installation records nor CISA’s evidence-receipt dates are part of the dataset. They also cannot establish whether exploitation began before or after the reference patches.
CVE Timeline Data
“Patch available” below means the selected upstream Linux 6.12.x release. The signed publication-to-patch column retains the actual sequence instead of forcing negative values to zero.
| CVE ID | CVE Published (D) | Reference Patch Available (P) | KEV Added (K) | Days: D → P | Days: P → K |
|---|---|---|---|---|---|
| CVE-2025-39964 | October 13, 2025 | 6.12.49 September 25, 2025 | September 18, 2026 | −18 | 358 |
| CVE-2026-53266 | June 25, 2026 | 6.12.94 June 19, 2026 | September 18, 2026 | −6 | 91 |
| CVE-2025-39682 | September 5, 2025 | 6.12.44 August 28, 2025 | September 18, 2026 | −8 | 386 |
The actual first-exploitation date is unavailable for each row. All three catalog due dates are September 21, 2026.
Selected historical fixed releases across upstream branches
| CVE ID | Linux 6.1.x | Linux 6.6.x | Linux 6.12.x |
|---|---|---|---|
| CVE-2025-39964 | 6.1.154 | 6.6.108 | 6.12.49 |
| CVE-2026-53266 | 6.1.176 | 6.6.143 | 6.12.94 |
| CVE-2025-39682 | 6.1.149 | 6.6.103 | 6.12.44 |
The branch values above were cross-checked against the Linux CNA CVE records and the matching kernel.org changelogs. These are selected fixed releases explicitly named in the CVE records, not a complete affected-product matrix or a recommendation to install those historical builds today. The 6.1.x and 6.6.x releases are not included in the timing calculations. Distribution-specific package and backport status require separate validation.
Statistical Distribution and Outliers
The shortest and longest reference-patch-to-KEV intervals differ by 295 days. The two longer observations, 358 and 386 days, are only 28 days apart; the third is 91 days. This describes a small, uneven sample rather than a stable industry distribution.
CVE-2026-53266 is the low-end observation and CVE-2025-39682 the high-end observation. With only three entries, neither is presented as a formally established statistical outlier. Their differences follow from their release dates relative to one shared KEV date; they do not prove that one weakness class was exploited faster.
Vulnerability Class Breakdown
| CVE ID | Affected Path | Catalog Weakness Class | Reference-Patch-to-KEV Gap |
|---|---|---|---|
| CVE-2025-39964 | AF_ALG socket writes | CWE-362 — Race condition | 358 days |
| CVE-2026-53266 | ebtables SNAT ARP address rewrite | CWE-787 — Out-of-bounds write | 91 days |
| CVE-2025-39682 | Kernel TLS receive-record handling | CWE-754 — Improper check for unusual or exceptional conditions | 386 days |
Each class has one observation. The table supports identification, not a class-level conclusion about typical patch or exploitation timing. A shared kernel product label also does not make every Linux installation reachable through each affected path.
Notable Case Highlights
CVE-2025-39964: concurrent writes and an 18-day publication difference
The flaw permits concurrent writes to the same AF_ALG socket to interleave and leave inconsistent internal state. The correction prevents concurrent writers in af_alg_sendmsg. Linux 6.12.49 included it on September 25, 2025, while the CVE record was published October 13. Its KEV addition followed 358 days after the reference release.
CVE-2026-53266: a writable-buffer correction with the shortest catalog interval
The ebtables SNAT issue concerns the optional ARP sender hardware address rewrite. The correction makes the relevant buffer range writable before updating it; safely reading a header alone does not establish that the destination is writable. Linux 6.12.94 included the fix on June 19, 2026, six days before CVE publication and 91 days before KEV addition. “Shortest” here refers only to that catalog interval.
CVE-2025-39682: a zero-length TLS record and the longest interval
A zero-length record retrieved from rx_list can bypass the expected record-type handling in recvmsg(), disrupting assumptions about later records. The correction appeared in Linux 6.12.44 on August 28, 2025. Formal CVE publication followed September 5; KEV inclusion came 386 days after the release. The affected receive path is kernel TLS, not a blanket description of every userspace TLS implementation.
Historical Trend Comparison
No comparable earlier cohort using the same upstream branch, publication convention, and KEV endpoint is available in the reviewed material. The result therefore cannot be described as a widening, narrowing, or stable historical trend.
A meaningful series comparison would hold those date definitions constant and account for branch selection and sample size. This article establishes one three-CVE observation, not a trend in exploitation speed.
MITRE ATT&CK Mapping
Technique-level mapping is unavailable for the observed exploitation in this dataset. The reviewed catalog and technical records describe vulnerable behavior and confirm known exploitation, but do not establish the attributable sequence of attacker actions needed for a campaign-specific mapping.
No initial-access, persistence, privilege-escalation, or command-and-control technique is assigned solely from a CWE, a possible impact, or the fact that a kernel component is affected.
Risk Context for Organizations
The operational concern is the status of affected systems when an established vulnerability gains a KEV designation. A long reference-patch-to-KEV interval is not evidence that an organization already deployed the fix, nor that a still-vulnerable system was safe during the interval.
| CVE ID | Catalog Due Date | Forensic-Triage Flag | Known Ransomware Campaign Use |
|---|---|---|---|
| CVE-2025-39964 | September 21, 2026 | Yes | Unknown |
| CVE-2026-53266 | September 21, 2026 | Yes | Unknown |
| CVE-2025-39682 | September 21, 2026 | Yes | Unknown |
These due dates had passed by the September 28 source review. “Unknown” ransomware use is not confirmation that ransomware activity is absent. The latter two entries also warn that impacted products could be end-of-life or end-of-service; that conditional warning does not classify every Linux product as unsupported.
The entries reference BOD 26-04 and its forensic-triage guidance. The directive addresses Federal Civilian Executive Branch agencies; the catalog dates should not be presented as universal legal deadlines for every organization. Elsewhere, the same information can inform an organization’s own risk and response requirements.
Detection and Patch Prioritization Considerations
Assess the deployed package, not just an upstream version string. Match the distribution, package revision, and applicable advisory to its backport status. The historical 6.12 releases explain the analysis; they are not a universal vulnerability-detection rule for vendor-maintained kernels.
Keep exposure assessment specific to the component. AF_ALG writes, ebtables SNAT rewriting, and kernel TLS receive processing are different paths. Kernel TLS receive support is configured separately through TLS_RX; ordinary use of HTTPS alone does not establish this particular receive-path exposure. Do not infer a shared remote attack surface from the kernel label.
Combine update validation with compromise assessment. The triage flags support treating evidence preservation and investigation as distinct response work, alongside mitigation. Confirm that corrected code is active through the platform-supported update or activation process. Record the deployed state, applicable exposure, and unresolved exceptions rather than equating an available patch with completed remediation.
Key Takeaways
- The three selected Linux kernel CVEs entered KEV on September 18, 2026; their reference Linux 6.12 fixes preceded inclusion by 91, 358, and 386 days.
- The reference-patch-to-KEV mean is 278.33 days and the median is 358 days; neither value is an observed attacker waiting period.
- All three selected fixed releases preceded formal CVE publication, showing why publication and public patch availability must remain separate events.
- No exact first-exploitation dates are established, so a patch-to-first-exploitation average or zero-day classification is unsupported by this analysis.
- Distribution backport status, active corrected code, component exposure, and compromise assessment require separate checks.
Conclusion
This cohort shows how a new KEV designation can concern vulnerabilities with substantially older fixes. On the common Linux 6.12 reference branch, the releases preceded catalog inclusion by 91 to 386 days, while the actual first-exploitation dates remain unresolved.
For patch and compliance monitoring, preserve the distinction between a published correction, a formal CVE record, evidence of known exploitation, and a verified deployed fix. Those separate milestones support an auditable response without inventing an attack timeline.
Constantly Fix Risks with Saner Patch Management
Saner Patch Management supports patch workflows across Windows, Linux, macOS, and more than 550 third-party applications. Its published capabilities include policy-driven automation, risk-based prioritization, patch-compliance tracking, and rollback.
Evaluate supported products and applicable updates for your environment, and connect patch deployment with verification and compliance reporting. Schedule a demonstration here.




