Exploited Vulnerabilities Daily
🌐 繁體中文

← 所有新增項目

CVE-2025-39682: Linux Kernel

Linux Kernel 包含了對 TLS 中異常或特殊條件脆弱性的不適當檢查,接收路徑允許從 rx_ list 中檢索到的零長記錄繞過預期的 recvmsg () 記錄型別處理,可能導致後續的 TLS 記錄使用錯誤的零複製和排隊假設進行處理。受影響的產品(產品)可能是終身(EoL)和/或終身(EoS)。建議使用者停止使用和/或向支援的版本過渡。

CISA (English)

Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

廠商
Linux
產品
Kernel
漏洞
Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
加入日期
2026年9月18日
CISA 修補期限(美國聯邦機關)
2026年9月21日
已知用於勒索軟體攻擊
未知
弱點(CWE)
CWE-754

參考資料

本站僅為資訊目的整理 CISA 目錄,並非資安建議。請遵循廠商指引與官方公告。

最後更新: · 目錄版本 2026.10.02