[UPDATE] [hoch] Linux Kernel: Mehrere Schwachstellen
Ein Angreifer kann mehrere Schwachstellen im Linux Kernel ausnutzen, um einen Denial of Service Angriff durchzuführen und andere nicht näher spezifizierte Angriffe durchzuführen, möglicherweise um beliebigen Code auszuführen oder eine Speicherbeschädigung zu verursachen.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to conduct denial of service attacks and perform other unspecified attacks, potentially executing arbitrary code or causing memory corruption.
- Who is affected
- All deployments of the Linux Kernel are affected.
- Urgency
- Remediation is urgent due to the high severity and potential for exploitation.
- Action
- Update to the latest kernel version to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Kernel
Get an email when a new Kernel advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-2170
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-398910.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-398920.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-398930.12% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-398940.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-398950.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-398960.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-398970.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-398990.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-399000.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiple vulnerabilities in Red Hat Linux kernel (August 21, 2026)cert-fr-avis
- mediumCVE-2025-39927: ceph: fix race condition validating r_parent before applying statemsrc
- highCVE-2025-39905: net: phylink: add lock for serializing concurrent pl->phydev writes with resolvermsrc
- highCVE-2025-39901: i40e: remove read access to debugfs filesmsrc
- criticalSiemens SINEC OScisa
Recent advisories for Linux Kernel
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriffcert-bund · 2026-09-07
- medium[UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Privilegieneskalation und Denial of Servicecert-bund · 2026-09-07
- high[NEU] [hoch] Linux Kernel: Mehrere Schwachstellencert-bund · 2026-09-07
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellencert-bund · 2026-09-07
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellencert-bund · 2026-09-07
- medium[UPDATE] [mittel] Linux Kernel: Schwachstelle ermöglicht Denial of Servicecert-bund · 2026-09-07
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [mittel] ILIAS: Mehrere Schwachstellen2026-09-08
- high[UPDATE] [hoch] Mozilla Firefox, Firefox ESR und Thunderbird: Mehrere Schwachstellen2026-09-07
- medium[UPDATE] [mittel] Linux Kernel: Mehrere Schwachstellen ermöglichen nicht spezifizierten Angriff2026-09-07
- high[UPDATE] [hoch] Google Chrome: Mehrere Schwachstellen2026-09-07
- high[UPDATE] [hoch] Mozilla Firefox und Thunderbird: Mehrere Schwachstellen2026-09-07