Skip to content
CVE Alert: CVE-2025-39964 – Linux

CVE Alert: CVE-2025-39964 – Linux

Redpacketsecurity •admin • September 18, 2026

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg – Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.

Treat this as an urgent, priority 1 vulnerability because exploitation is marked active and compromise can provide complete local kernel-level impact.

An unprivileged local user may be able to crash the host, disclose protected kernel memory or achieve privilege escalation. The main business risks are host takeover, disruption of critical services, loss of confidentiality and, where the host supports operational technology, interruption or manipulation of industrial processes. Exploitation is not remotely reachable by itself, but becomes serious after initial access through a compromised account, workload or container.

### Most likely attack path

An attacker executes locally with low privileges and no user interaction, creates and binds an AF_ALG socket, then races concurrent writes using two threads. Low complexity and full attacker control of the race make reliable exploitation plausible. Scope remains within the host’s security authority, but successful privilege escalation could enable access to other services, credentials and workloads on that system.

### Who is most exposed

Prioritise multi-tenant Linux servers, container hosts, shared compute platforms and systems allowing untrusted local code. Embedded or industrial Linux appliances deserve special attention where patching is constrained and availability is safety- or production-critical.

Alert on unusual AF_ALG socket creation by non-system accounts.

Correlate rapid concurrent `sendmsg` activity with crypto socket use.

Investigate kernel oopses, panics, slab corruption or unexplained reboots.

Review new privileged processes following crypto-related syscall activity.

### Mitigation and prioritisation

**Treat as priority 1**; deploy the vendor kernel security update at the earliest safe opportunity.

Confirm running, not merely installed, kernel versions across hosts and appliances.

Restrict untrusted local code, containers and user namespaces where operationally viable.

Consider disabling or limiting AF_ALG only after testing application dependencies.

Use staged maintenance and rollback plans for industrial or high-availability systems.

A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.

If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.

Extracted Entities