๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2025-39682: Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
Summary
A bug in the Linux Kernel's TLS (Transport Layer Security, the protocol that encrypts internet traffic) receive path allows a zero-length record to bypass security checks, which could cause subsequent TLS records to be processed incorrectly. Systems running end-of-life or unsupported versions are especially at risk, and users should either apply fixes or switch to supported versions.
Solution / Mitigation
Apply mitigations according to vendor instructions and follow CISA's BOD 26-04 (Prioritizing Security Updates Based on Risk) guidance. If mitigations are unavailable, discontinue use of the product. Specific patches are available at: https://git.kernel.org/stable/c/2902c3ebcca52ca845c03182000e8d71d3a5196f, https://git.kernel.org/stable/c/c09dd3773b5950e9cfb6c9b9a5f6e36d06c62677, https://git.kernel.org/stable/c/3439c15ae91a517cf3c650ea15a8987699416ad9, https://git.kernel.org/stable/c/29c0ce3c8cdb6dc5d61139c937f34cb888a6f42e, and https://git.kernel.org/stable/c/62708b9452f8eb77513115b17c4f8d1a22ebf843.
Vulnerability Details
EPSS: 0.5%
Yes
๐ฅ Actively Exploited
September 17, 2026
Classification
Taxonomy References
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-39682
First tracked: September 18, 2026 at 08:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%