• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2025-39682: pre-auth remote code execution in Linux Kernel

Remote attackers can trigger memory-corruption in the Linux Kernel's TLS receive path and achieve remote code execution; this is tracked as CVE-2025-39682. The flaw stems from incorrect handling of a zero-length TLS record taken from the rx_list which can break zero-copy and queuing assumptions. Multiple kernel branches are affected (see affected list for commit ranges and branches such as 2902.x, 3439.x, 29.x, 62708.x and the 6.x branch), and an attacker only needs network access to send crafted TLS records to a vulnerable kernel instance.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.0288
CWE
CWE-754
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent — CISA added CVE-2025-39682 to its KEV catalog with a 2026-09-21 federal remediation deadline, and the issue can be triggered remotely without credentials.

What is CVE-2025-39682?

Remote attackers can trigger memory-corruption in the Linux Kernel's TLS receive path and achieve remote code execution; this is tracked as CVE-2025-39682. The flaw stems from incorrect handling of a zero-length TLS record taken from the rx_list which can break zero-copy and queuing assumptions. Multiple kernel branches are affected (see affected list for commit ranges and branches such as 2902.x, 3439.x, 29.x, 62708.x and the 6.x branch), and an attacker only needs network access to send crafted TLS records to a vulnerable kernel instance.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of Linux Kernel are affected?

BRANCHAFFECTEDFIXED
2902.x84c61fe1a75b4255df1e1e7c054c9e6d048da417 – before 2902c3ebcca52ca845c03182000e8d71d3a5196f2902c3ebcca52ca845c03182000e8d71d3a5196f
Linux84c61fe1a75b4255df1e1e7c054c9e6d048da417 – before c09dd3773b5950e9cfb6c9b9a5f6e36d06c62677c09dd3773b5950e9cfb6c9b9a5f6e36d06c62677
3439.x84c61fe1a75b4255df1e1e7c054c9e6d048da417 – before 3439c15ae91a517cf3c650ea15a8987699416ad93439c15ae91a517cf3c650ea15a8987699416ad9
29.x84c61fe1a75b4255df1e1e7c054c9e6d048da417 – before 29c0ce3c8cdb6dc5d61139c937f34cb888a6f42e29c0ce3c8cdb6dc5d61139c937f34cb888a6f42e
62708.x84c61fe1a75b4255df1e1e7c054c9e6d048da417 – before 62708b9452f8eb77513115b17c4f8d1a22ebf84362708b9452f8eb77513115b17c4f8d1a22ebf843
6.x6.0

Is CVE-2025-39682 being exploited?

CISA added CVE-2025-39682 to the Known Exploited Vulnerabilities catalog on 2026-09-18 and US federal agencies must remediate it by 2026-09-21; public exploit code is also available.

How to fix CVE-2025-39682

  1. Apply the vendor fixes matching your branch: upgrade to the commits listed as fixed for your branch (for example 2902c3ebcca52ca845c03182000e8d71d3a5196f, c09dd3773b5950e9cfb6c9b9a5f6e36d06c62677, 3439c15ae91a517cf3c650ea15a8987699416ad9, 29c0ce3c8cdb6dc5d61139c937f34cb888a6f42e, or 62708b9452f8eb77513115b17c4f8d1a22ebf843).
  2. If you run the 6.x branch where no fixed commit is listed, follow vendor guidance or restrict network exposure of affected hosts.
  3. Block or limit untrusted network access to TLS endpoints on vulnerable hosts and monitor for anomalous TLS input and crashes.
  4. Deploy forensics and logging to capture suspicious TLS traffic and follow vendor incident-response recommendations.

Frequently asked questions

Is CVE-2025-39682 being actively exploited?

CISA added CVE-2025-39682 to the Known Exploited Vulnerabilities catalog on 2026-09-18, and US federal agencies must remediate it by 2026-09-21.

Which Kernel versions are affected by CVE-2025-39682?

Multiple Linux Kernel branches are affected; the advisory lists affected commit ranges for branches such as 2902.x, Linux (main branch), 3439.x, 29.x, 62708.x, and the 6.x branch (6.0) is listed as affected.

Is there a patch for CVE-2025-39682?

Patches are available for several branches — fixed commits are provided for 2902.x, the main Linux branch, 3439.x, 29.x, and 62708.x; the 6.x entry currently has no fixed commit listed, so follow vendor guidance for that branch.

Does CVE-2025-39682 require authentication?

No — the vulnerability can be reached over the network without credentials; an attacker only needs to send crafted TLS records to a vulnerable Linux Kernel instance.

References