Federal agencies must patch three critical kernel vulnerabilities within 72 hours after CISA adds them to its Known Exploited Vulnerabilities catalog.
CISA has added three actively exploited Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, mandating that all federal agencies apply patches within 72 hours, with a deadline of Sunday.
Vulnerabilities Added to the KEV Catalog
The three flaws affect the Linux kernel’s networking and memory management subsystems. They are designated CVE‑2023‑XXXX, CVE‑2023‑YYYY, and CVE‑2023‑ZZZZ, each rated as critical by the National Vulnerability Database.
All three vulnerabilities have been observed in the wild, with threat actors leveraging them to gain elevated privileges, execute arbitrary code, or cause denial‑of‑service conditions on compromised systems.
Patch Timeline and Compliance Requirements
CISA’s directive gives agencies until Sunday midnight to deploy the vendor‑provided patches. Agencies must document compliance and report any remediation challenges to the agency’s cybersecurity liaison.
Failure to meet the deadline could result in increased risk of intrusion, as the vulnerabilities are actively weaponized against unpatched systems across the federal landscape.
Mitigation Steps for Agencies
- Verify the kernel version and identify if any of the three CVEs apply.
- Apply the latest security updates released by the Linux distribution vendor.
- Restart affected services or reboot systems to ensure the patched kernel is loaded.
- Document the patching process and submit compliance reports to CISA.
Agencies are also advised to monitor network traffic for indicators of compromise related to these exploits and to isolate any systems that cannot be patched immediately.
"Timely patching is the most effective defense against active exploits," said a CISA spokesperson.
For detailed guidance, agencies can consult the CISA KEV catalog and the associated mitigation bulletin released alongside the announcement.