Skip to content

CVE-2025-39964

7.8 HIGHActively exploited (CISA KEV)EPSS 0.32%
  1. Published13 Oct 2025
  2. Added to CISA KEV18 Sept 2026
  3. Remediation due21 Sept 2026
Actively exploited (CISA KEV)

Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.

Added to KEV: 18 Sept 2026Federal remediation due: 21 Sept 2026

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.

CVSS 3.1 breakdown

Attack vectorLocal
Attack complexityLow
Privileges requiredLow
User interactionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

Linux Linux Kernel≥ 2.6.38 < 5.10.245 · ≥ 5.11 < 5.15.194 · ≥ 5.16 < 6.1.154 · ≥ 6.13 < 6.16.9

Frequently asked

Is CVE-2025-39964 being actively exploited?

Yes. CVE-2025-39964 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added 18 Sept 2026.

How severe is CVE-2025-39964?

CVE-2025-39964 has a CVSS 3.1 base score of 7.8, rated high. EPSS estimates a 0.32% probability of exploitation.

Which products are affected by CVE-2025-39964?

Affected products include Linux Linux Kernel.

How do I fix CVE-2025-39964?

Upgrade affected software to a fixed version, for example Linux Linux Kernel 5.10.245 or later, then confirm no affected versions remain in your inventory.

How Secuno handles this

Secuno correlates vulnerabilities like CVE-2025-39964 against the real software inventory on every managed device, every day. Rather than a static severity, each match is scored in context: exploit availability, EPSS, the asset's exposure, and business criticality decide where it lands in the queue. Because it is on the CISA KEV list, Secuno flags any affected asset as top-priority automatically. If an affected version is present anywhere across your portfolio, it surfaces automatically with a prioritised remediation path.

Data from the NVD, CISA KEV catalog and FIRST EPSS. CVSS 3.1 base score shown where available.