Exploited Vulnerabilities Daily
🌐 English

← All new entries

CVE-2025-39682: Linux Kernel

Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

Vendor
Linux
Product
Kernel
Vulnerability
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
Date added
Sep 18, 2026
CISA due date (U.S. federal agencies)
Sep 21, 2026
Known ransomware campaign use
Unknown
Weakness (CWE)
CWE-754

References

This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.

Last updated: · Catalog version 2026.10.02