Exploited Vulnerabilities Daily
🌐 한국어

← 전체 신규 항목

CVE-2025-39682: Linux Kernel

Linux Kernel은 TLS의 비정상적인 또는 예외적 인 조건 취약점에 대한 부적절한 검사를 포함하면 rx_list에서 Zero-length 레코드를 재생할 수 있는 경로가 의도한 recvmsg() 레코드 유형 취급을 우회할 수 있습니다. 잠재적으로 인해 TLS 레코드가 0-copy 및 쿼싱 가정을 사용하여 처리됩니다. 충격 제품 (s)는 end-of-life (EoL) 및/또는 end-of-service (EoS)일 수 있었습니다. 사용자는 지원되는 버전으로 사용 및/또는 전환을 중단하는 것이 좋습니다.

CISA (English)

Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

공급업체
Linux
제품
Kernel
취약점
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
추가일
2026. 9. 18.
CISA 조치 기한(미국 연방기관)
2026. 9. 21.
랜섬웨어 공격 악용
알 수 없음
약점(CWE)
CWE-754

참고 자료

이 사이트는 정보 제공 목적으로 CISA 카탈로그를 요약한 것이며 보안 조언이 아닙니다. 공급업체 안내와 공식 권고를 따르세요.

최종 업데이트: · 카탈로그 버전 2026.10.02