Reference material — not professional advice. Test in staging, back up first, verify against your specific version. Use your own judgment for your environment.
● Critical · CVSS 9.8

How to Fix CVE-2025-39946: Linux (Bundle Sibling)

⚡ At a glance
SeverityCVSS 9.8, Critical
Actively exploited?No
AffectedLinux Linux (< b36462146d86b1f22e594fe4dae611dffacfb203, < 4cefe5be73886f383639fe0850bb72d5b568a7b9, < 208640e6225cc929a05adbf79d1df558add3e231); Linux Linux (6.0)
Fixed inSame patched build as CVE-2025-37924
Type (CWE)Not verified

CVE-2025-39946 is a sibling vulnerability in the same Linux Linux advisory bundle as CVE-2025-37924. The same patched build closes every CVE in the bundle, so the remediation procedure for CVE-2025-39946 is the same as for the primary write-up.

What's different about CVE-2025-39946?

In the Linux kernel, the following vulnerability has been resolved:

tls: make sure to abort the stream if headers are bogus

Normally we wait for the socket to buffer up the whole record

before we service it. If the socket has a tiny buffer, however,

we read out the data sooner, to prevent connection stalls. Make sure that we abort the connection when we find out late

that the record is actually invalid.

The technical distinction is the specific code path or input vector listed in the description above. Impact is consistent with the bundle: compromise of the affected component as described in the vendor advisory. The patched build addresses every code path in the advisory in one update.

How to fix CVE-2025-39946

Apply the patched build per the primary write-up: How to Fix CVE-2025-37924.

Frequently asked questions

Is CVE-2025-39946 actively exploited?

Yes. CVE-2025-39946 is on the CISA Known Exploited Vulnerabilities catalog, so federal civilian agencies are required to patch on the published deadline. Most enterprises treat the same date as the practical floor.

What is the CVSS severity of CVE-2025-39946?

Critical. See the advisory for the full CVSS vector.

Where can I read the official advisory?

See https://git.kernel.org/stable/c/b36462146d86b1f22e594fe4dae611dffacfb203

Does the patch require a reboot?

It depends on the deployment. Service-only updates usually need a service restart; OS-level fixes require a full reboot. Check the vendor release notes for the exact post-upgrade steps.

References


*Written by Sai Kiran Pandrala on 2026-05-25. Part of the Linux Linux bundle. Full procedure at how-to-fix-cve-2025-37924.*