Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2025-39682
CVE
CVE-2025-39682
View on NVD ↗
tls: fix handling of zero-length records on the rx_list
Source Articles
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation in the wild. The vulnerabilities—CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964—allow local attackers to achieve memory disclosure, denial-of-service, or local privilege escalation. Red Hat has acknowledged active exploitation and labeled the flaws as high risk, urging immediate remediation. Federal agencies are required to patch these vulnerabilities by September 21, 2026, per Binding Operational Directive 26-04.
hacker-news
Sep 19, 2026