CVE Tools

CVE-2025-39964

crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg

Published: Oct 13, 2025Updated: Sep 19, 2026 Sources: CVE List NVD BDU csafCWE-362

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.

In plain language

AI Act now

This is a serious flaw in the Linux kernel that attackers are actively using; update systems that have not received the vendor fix, including Linux kernel 5.10 systems before 5.10.245.

Executive summary

A locally authenticated attacker can exploit a race condition in Linux kernel AF_ALG socket handling by issuing concurrent writes, potentially compromising confidentiality, integrity, and availability.

If affected, business impact
Full system compromiseBusiness data exposureService disruptionRansomware risk

What to do now

  1. Ask IT to identify every server, workstation, appliance, and virtual machine running the Linux kernel and record its installed kernel version.
  2. Install your operating-system or device vendor’s security update containing the fix; for the 5.10 branch, update to 5.10.245 or later.
  3. Restart updated systems into the new kernel and confirm the running version after reboot.
  4. If an update is unavailable, restrict untrusted local accounts and container workloads until the vendor provides a fixed release.
Patch / advisory Usually a quick update

CVSS Vector Breakdown

AV:LAC:LPR:LUI:NS:UC:HI:HA:H
Exploitability
AV:LAttack Vector
Local
AC:LAttack Complexity
Low
PR:LPrivileges Required
Low
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 1 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Sep 18, 2026
Remediation due:Sep 21, 2026

Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

1 exploit source identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Privilege Escalation
View detailed technique mapping

References

and 496 more references View all →
1

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2025-39964 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows