Actively exploited vulnerability
Linux Kernel: security bypass flaw under attack
CVE-2025-39682 · Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
What is affected
Linux Kernel is found on ordinary personal computers and phones, so this is not only a problem for companies. If you use it and have not updated since the fix was released, you are exposed.
Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.
What an attacker can do
This is a security bypass flaw. It lets an attacker slip past a built-in protection, so warnings and checks that normally stop malicious content never appear.
- How it is reached
- Over the internet or network
- Access the attacker needs
- No account needed
- Does the victim have to do something?
- No, works without the victim doing anything
What to do
- Update Linux Kernel now. Open the update or "About" screen, install whatever is offered and restart the app or device, because the fix is not active until you do.
- Turn on automatic updates so the next fix arrives without you having to look for it.
- If your device is too old to receive this update, stop using the affected app for anything sensitive and plan a replacement.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Vendor advisories and fixes
- git.kernel.orggit.kernel.org/stable/c/2902c3ebcca52ca845c03182000e8d71d3a5196f
- git.kernel.orggit.kernel.org/stable/c/c09dd3773b5950e9cfb6c9b9a5f6e36d06c62677
- git.kernel.orggit.kernel.org/stable/c/3439c15ae91a517cf3c650ea15a8987699416ad9
- git.kernel.orggit.kernel.org/stable/c/29c0ce3c8cdb6dc5d61139c937f34cb888a6f42e
- git.kernel.orggit.kernel.org/stable/c/62708b9452f8eb77513115b17c4f8d1a22ebf843
How urgent is it
CISA added this vulnerability to its Known Exploited Vulnerabilities catalogue on September 18, 2026, which means there is reliable evidence of attacks in the wild. US federal agencies must fix it by September 21, 2026, a deadline that has already passed. That deadline does not bind anyone else, but it shows how seriously the agency rates it.
The EPSS model estimates a 2.9% probability that this flaw will be exploited somewhere in the next 30 days. That is higher than 86% of all scored vulnerabilities.
Its CVSS severity score is 9.8 out of 10 (critical), as recorded in the US National Vulnerability Database.
Technical description
In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA record If the next record has different type than what has already been processed we break out of the main processing loop. If the record has already been decrypted (which may be the case for TLS 1.3 where we don't know type until decryption) we queue the pending record to the rx_list. Next recvmsg() will pick it up from there. Queuing the skb to rx_list after zero-copy decrypt is not possible, since in that case we decrypted directly to the user space buffer, and we don't have an skb to queue (darg.skb points to the ciphertext skb for access to metadata like length). Only data records are allowed zero-copy, and we break the processing loop after each non-data record. So we should never zero-copy and then find out that the record type has changed. The corner case we missed is when the initial record comes from rx_list, and it's zero length.