CVE-2025-39964
crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.
In plain language
AI Act nowThis is a serious flaw in the Linux kernel that attackers are actively using; update systems that have not received the vendor fix, including Linux kernel 5.10 systems before 5.10.245.
A locally authenticated attacker can exploit a race condition in Linux kernel AF_ALG socket handling by issuing concurrent writes, potentially compromising confidentiality, integrity, and availability.
What to do now
- Ask IT to identify every server, workstation, appliance, and virtual machine running the Linux kernel and record its installed kernel version.
- Install your operating-system or device vendor’s security update containing the fix; for the 5.10 branch, update to 5.10.245 or later.
- Restart updated systems into the new kernel and confirm the running version after reboot.
- If an update is unavailable, restrict untrusted local accounts and container workloads until the vendor provides a fixed release.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-39964 and every CVE in our database. Create a free account — no credit card required.
Create Free Account