CVE-2025-39964
- Published13 Oct 2025
- Added to CISA KEV18 Sept 2026
- Remediation due21 Sept 2026
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.
CVSS 3.1 breakdown
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAffected products
Remediation
- https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce
- https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285
- https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8
- https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042
- https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84
- https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d
References
- https://cert-portal.siemens.com/productcert/html/ssa-019113.html
- https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce
- https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285
- https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8
- https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042
- https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84
- https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d
- https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-39964
Related CVEs
Recent high-severity vulnerabilities sharing a weakness type.
Frequently asked
Is CVE-2025-39964 being actively exploited?
Yes. CVE-2025-39964 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added 18 Sept 2026.
How severe is CVE-2025-39964?
CVE-2025-39964 has a CVSS 3.1 base score of 7.8, rated high. EPSS estimates a 0.32% probability of exploitation.
Which products are affected by CVE-2025-39964?
Affected products include Linux Linux Kernel.
How do I fix CVE-2025-39964?
Upgrade affected software to a fixed version, for example Linux Linux Kernel 5.10.245 or later, then confirm no affected versions remain in your inventory.
How Secuno handles this
Secuno correlates vulnerabilities like CVE-2025-39964 against the real software inventory on every managed device, every day. Rather than a static severity, each match is scored in context: exploit availability, EPSS, the asset's exposure, and business criticality decide where it lands in the queue. Because it is on the CISA KEV list, Secuno flags any affected asset as top-priority automatically. If an affected version is present anywhere across your portfolio, it surfaces automatically with a prioritised remediation path.
Data from the NVD, CISA KEV catalog and FIRST EPSS. CVSS 3.1 base score shown where available.