CVE-2025-39682: Linux Kernel
Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
- Nhà cung cấp
- Linux
- Sản phẩm
- Kernel
- Lỗ hổng
- Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
- Ngày thêm
- 18 thg 9, 2026
- Hạn của CISA (cơ quan liên bang Hoa Kỳ)
- 21 thg 9, 2026
- Bị dùng trong chiến dịch mã độc tống tiền
- Chưa rõ
- Điểm yếu (CWE)
- CWE-754
Tài liệu tham khảo
- NVD — CVE-2025-39682
- git.kernel.org
- git.kernel.org
- git.kernel.org
- git.kernel.org
- git.kernel.org
- www.cisa.gov
- www.cisa.gov
- nvd.nist.gov
Trang này tóm tắt danh mục của CISA chỉ nhằm cung cấp thông tin, không phải lời khuyên bảo mật. Hãy làm theo hướng dẫn của nhà cung cấp và các khuyến cáo chính thức.
Cập nhật lần cuối: · Phiên bản danh mục 2026.10.02