CVE-2025-39964

Executive Summary

CVE-2025-39964 exposes a flaw in the Linux kernel’s crypto af_alg socket implementation: concurrent writes to the same socket interleave unpredictably and can corrupt internal socket state. The issue is actively exploited (CISA KEV). The patch introduces a write ownership flag to serialize access, preventing data corruption and state inconsistencies.


Authoritative CVE Metadata - CVSS Base Score: 7.8 (HIGH) - Published: 2025-10-13T14:15:34.737 - Last Modified: 2026-09-19T04:17:48.307

[!CAUTION] Known Exploited Vulnerability: YES (CISA KEV Added: 2026-09-18)

Original Description: In the Linux kernel, the following vulnerability has been resolved:

crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg

Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state.

Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.

"An optimist is a person who sees a green light everywhere, while the pessimist sees only the red spotlight... The truly wise person is colour-blind."

— Albert Schweitzer
Source: NVD