DIRAS TAKE
Urgent — CISA added CVE-2025-39682 to its KEV catalog with a 2026-09-21 federal remediation deadline, and the issue can be triggered remotely without credentials.
What is CVE-2025-39682?
Remote attackers can trigger memory-corruption in the Linux Kernel's TLS receive path and achieve remote code execution; this is tracked as CVE-2025-39682. The flaw stems from incorrect handling of a zero-length TLS record taken from the rx_list which can break zero-copy and queuing assumptions. Multiple kernel branches are affected (see affected list for commit ranges and branches such as 2902.x, 3439.x, 29.x, 62708.x and the 6.x branch), and an attacker only needs network access to send crafted TLS records to a vulnerable kernel instance.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of Linux Kernel are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 2902.x | 84c61fe1a75b4255df1e1e7c054c9e6d048da417 – before 2902c3ebcca52ca845c03182000e8d71d3a5196f | 2902c3ebcca52ca845c03182000e8d71d3a5196f |
| Linux | 84c61fe1a75b4255df1e1e7c054c9e6d048da417 – before c09dd3773b5950e9cfb6c9b9a5f6e36d06c62677 | c09dd3773b5950e9cfb6c9b9a5f6e36d06c62677 |
| 3439.x | 84c61fe1a75b4255df1e1e7c054c9e6d048da417 – before 3439c15ae91a517cf3c650ea15a8987699416ad9 | 3439c15ae91a517cf3c650ea15a8987699416ad9 |
| 29.x | 84c61fe1a75b4255df1e1e7c054c9e6d048da417 – before 29c0ce3c8cdb6dc5d61139c937f34cb888a6f42e | 29c0ce3c8cdb6dc5d61139c937f34cb888a6f42e |
| 62708.x | 84c61fe1a75b4255df1e1e7c054c9e6d048da417 – before 62708b9452f8eb77513115b17c4f8d1a22ebf843 | 62708b9452f8eb77513115b17c4f8d1a22ebf843 |
| 6.x | 6.0 |
Is CVE-2025-39682 being exploited?
CISA added CVE-2025-39682 to the Known Exploited Vulnerabilities catalog on 2026-09-18 and US federal agencies must remediate it by 2026-09-21; public exploit code is also available.
How to fix CVE-2025-39682
- Apply the vendor fixes matching your branch: upgrade to the commits listed as fixed for your branch (for example 2902c3ebcca52ca845c03182000e8d71d3a5196f, c09dd3773b5950e9cfb6c9b9a5f6e36d06c62677, 3439c15ae91a517cf3c650ea15a8987699416ad9, 29c0ce3c8cdb6dc5d61139c937f34cb888a6f42e, or 62708b9452f8eb77513115b17c4f8d1a22ebf843).
- If you run the 6.x branch where no fixed commit is listed, follow vendor guidance or restrict network exposure of affected hosts.
- Block or limit untrusted network access to TLS endpoints on vulnerable hosts and monitor for anomalous TLS input and crashes.
- Deploy forensics and logging to capture suspicious TLS traffic and follow vendor incident-response recommendations.
Frequently asked questions
Is CVE-2025-39682 being actively exploited?
CISA added CVE-2025-39682 to the Known Exploited Vulnerabilities catalog on 2026-09-18, and US federal agencies must remediate it by 2026-09-21.
Which Kernel versions are affected by CVE-2025-39682?
Multiple Linux Kernel branches are affected; the advisory lists affected commit ranges for branches such as 2902.x, Linux (main branch), 3439.x, 29.x, 62708.x, and the 6.x branch (6.0) is listed as affected.
Is there a patch for CVE-2025-39682?
Patches are available for several branches — fixed commits are provided for 2902.x, the main Linux branch, 3439.x, 29.x, and 62708.x; the 6.x entry currently has no fixed commit listed, so follow vendor guidance for that branch.
Does CVE-2025-39682 require authentication?
No — the vulnerability can be reached over the network without credentials; an attacker only needs to send crafted TLS records to a vulnerable Linux Kernel instance.
References
- nvd.nist.gov/vuln/detail/CVE-2025-39682
- cve.org/CVERecord?id=CVE-2025-39682
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-39682
- git.kernel.org/stable/c/2902c3ebcca52ca845c03182000e8d71d3a5196f
- git.kernel.org/stable/c/c09dd3773b5950e9cfb6c9b9a5f6e36d06c62677
- git.kernel.org/stable/c/3439c15ae91a517cf3c650ea15a8987699416ad9
- git.kernel.org/stable/c/29c0ce3c8cdb6dc5d61139c937f34cb888a6f42e
- git.kernel.org/stable/c/62708b9452f8eb77513115b17c4f8d1a22ebf843
- All Linux CVEs on CVE Radar
- CVEs published in September 2026