A technical case study on defending Linux kernel zero-days (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682) without downtime using layered compensating controls including eBPF telemetry, kernel module disarmament, and user namespaces. The framework bridges the 7–21 day gap between public vulnerability disclosure and vendor patch availability by combining syscall gating, module eviction/sealing, and automated remediation pipelines.