CVE-2025-39946 — Out-of-bounds Write in Linux
Severity
5.5MEDIUMNVD
OSV3.2
EPSS
0.0%
top 95.04%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 4
Latest updateMar 25
Description
In the Linux kernel, the following vulnerability has been resolved:
tls: make sure to abort the stream if headers are bogus
Normally we wait for the socket to buffer up the whole record
before we service it. If the socket has a tiny buffer, however,
we read out the data sooner, to prevent connection stalls.
Make sure that we abort the connection when we find out late
that the record is actually invalid. Retrying the parsing is
fine in itself but since we copy some more data each time
before we…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages8 packages
Patches
🔴Vulnerability Details
24OSV▶
CVE-2025-39946: In multiple locations, there is a possible out of bounds write due to a missing bounds check↗2026-03-01