CVE-2025-39682 — Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

CVE-2025-39682 in Linux Kernel is listed in the CISA Known Exploited Vulnerabilities catalog (added 2026-09-18). Required action, remediation due date, ransomware association, EPSS score and vendor advisories.

Exploitation status

CVE-2025-39682 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added 2026-09-18. Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

Advisory facts

Vendor or project
Linux
Affected product
Kernel
Added to CISA KEV
2026-09-18
US federal remediation due date
2026-09-21
Ransomware association
Unknown
EPSS score
Weakness (CWE)
CWE-754

Remediation: the required action

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Wording published by CISA for this catalog entry. It is the baseline action, not a decision about your environment: whether this exposure matters for you depends on where the affected component runs, what it is exposed to and who owns it.

From advisory to a decision you can defend

A catalog entry tells you a vulnerability is being exploited somewhere. It does not tell you whether it matters in your estate, who owns the fix, or what evidence an auditor will ask for later. That is the work VulnTrek does: it takes findings from the tools you already run, decides which exposure actually matters, routes it to an owner, keeps remediation human-approved and retains the lineage as evidence.

Sourced from public upstream advisories (CISA KEV, ENISA EUVD, vendor PSIRTs) mirrored daily. Informational only — not a remediation decision, not legal advice, and the absence of a record is not evidence of safety.