CISA Adds One Known Exploited Vulnerability to Catalog
CISA added actively exploited Linux kernel flaw CVE-2025-39682 to its KEV catalog, requiring federal agencies to prioritize remediation under BOD 26-04.
CISA added CVE-2025-39682, an improper check for unusual or exceptional conditions in the Linux kernel, to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. Under Binding Operational Directive 26-04, Federal Civilian Executive Branch agencies must prioritize rapid remediation of KEV-listed vulnerabilities on publicly exposed assets that grant total control post-exploitation, and must check whether systems were compromised before patching. CISA encourages all organizations to adopt risk-based vulnerability management and prioritize KEV remediation.
- CVE-2025-39682: Linux kernel improper check for unusual or exceptional conditions
- Added to KEV Catalog based on evidence of active exploitation
- BOD 26-04 mandates rapid federal remediation of KEV vulnerabilities
- Agencies must verify whether systems were compromised before patching
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-39682 | Improper Condition Check in Linux Kernel kTLS Receive Path Enables Local Info Leak/DoS The Linux kernel's in-kernel TLS (kTLS) implementation mishandles zero-length records on the rx_list: each recvmsg() call must process either contiguous DATA records or a single non-DATA record, and the missed corner case occurs when the initial record is pulled from the rx_list and is zero length, breaking the check on record-type changes after zero-copy decryption. A local, low-privileged attacker able to use kTLS sockets can trigger this flaw, and the CVSS vector indicates high confidentiality impact (kernel information disclosure) and high availability impact (crash/DoS), with no integrity impact. Any Linux deployment running a kernel with the TLS (kTLS) feature enabled is affected, including Debian systems, which are listed as affected vendors in CISA's data. CISA added this vulnerability to the Known Exploited Vulnerabilities catalog on 2026-09-18, indicating known exploitation in the wild, though no public proof-of-concept is known and ransomware use is unconfirmed. Do: Update the Linux kernel to a release containing the upstream fix for this kTLS rx_list issue, applying Debian security updates where applicable, consistent with CISA BOD 26-04 patching guidance. As an interim mitigation, check whether kernel TLS is active (e.g., 'lsmod | grep tls' or CONFIG_TLS in the running kernel) and unload/disable the tls module on hosts that do not require kTLS. Limit local unprivileged access on multi-user systems, since exploitation requires a local low-privileged user. | 7.1 | 1% | KEV |
| mass≈100M+ systems potentially exposed (Linux kernel ubiquitous; only hosts with the kTLS module enabled and in use are vulnerable) |
Full article226 words · extracted from cisa.gov · click to collapse
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
- CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied.
While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-one-known-exploited-vulnerability-catalog