CVE-2025-39964
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.
- Published Oct 13, 2025
- CVSS 5.5 medium
- 1.3% chance of exploitation in the next 30 days (EPSS)
- In CISA's Known Exploited Vulnerabilities catalog
- A fix is available
Affected software
In the news
- Multiple vulnerabilities in the Red Hat Linux kernel CERT-FR ·
- Multiple vulnerabilities in the SUSE Linux kernel CERT-FR ·
- Multiple vulnerabilities in the Red Hat Linux kernel CERT-FR ·
- CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild The Hacker News ·
- CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA ·
- Multiple vulnerabilities in the SUSE Linux kernel CERT-FR ·