CVE-2025-39682
tls: fix handling of zero-length records on the rx_list
Description
SIMATIC CN 4100 contains multiple vulnerabilities which could potentially lead to a compromise in availability, integrity and confidentiality. Siemens has released a new version for SIMATIC CN 4100 and recommends to update to the latest version.
In plain language
AI Act nowThis is a critical flaw in unpatched Linux kernel systems that attackers are already using, so small businesses running Linux servers should treat it as an emergency.
CVE-2025-39682 is a network-reachable Linux kernel TLS handling flaw involving zero-length records on the rx_list, with impacts to confidentiality, integrity, and availability.
What to do now
- Check every Linux server and appliance for its running kernel version and confirm with its operating-system vendor whether its installed security package includes CVE-2025-39682.
- Install the vendor-provided kernel security update; for the upstream 6.1 branch, update to 6.1.149 or later.
- Restart into the updated kernel and verify the running version after reboot.
- If an update cannot be applied immediately, follow your vendor's mitigation guidance and prioritize internet-facing systems.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-39682 and every CVE in our database. Create a free account — no credit card required.
Create Free Account