CVE-2025-39964

● KEV MEDIUM

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data...

Affects 1 product across 2 vendors.

BCS2.66
CVSS 3.15.5
EPSS1.0%
Percentile61th
PatchUnknown
KEV Added2026-09-18
CVSS Vector — Plain English Requires local access, low complexity, low privileges required, no user interaction needed, impact contained to the vulnerable component, no confidentiality impact, no integrity impact, full availability impact.
CWE Weakness Definitions
CWE-362: Race Condition

Software behavior depends on event timing that is not enforced, allowing attackers to exploit the timing window.

Related Attack Patterns (CAPEC)
CAPEC-29 Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race Conditions
via CWE-362
CAPEC-26 Leveraging Race Conditions
via CWE-362

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A vulnerability in the Linux kernel's crypto: af_alg module allows for concurrent writes to the same af_alg socket, leading to data interleaving and potential inconsistencies in the internal socket state.

BSID: BS-2025-GLOBAL-269863-L • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-39964?
A vulnerability in the Linux kernel's crypto: af_alg module allows for concurrent writes to the same af_alg socket, leading to data interleaving and potential inconsistencies in the internal socket state.
What is the CVSS score for CVE-2025-39964?
CVE-2025-39964 has CVSS 5.5 (Medium). Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H. EPSS: 1.0%.
Is CVE-2025-39964 actively exploited?
Yes. CVE-2025-39964 is in the CISA KEV catalog (added 2026-09-18). Active exploitation confirmed. Immediate patching required.
How do I remediate CVE-2025-39964?
Priority: MEDIUM. Advisory: https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce
What systems are affected by CVE-2025-39964?
CVE-2025-39964 affects: Linux, Siemens.
Vulnerability Details
CVE IDCVE-2025-39964
BSIDBS-2025-GLOBAL-269863-L BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Published2026-07-28
Last Modified2026-09-19
ICS Relevance85%
Weakness (CWE)
SourceNVD
Official Description

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker could exploit this vulnerability by issuing concurrent writes to the same af_alg socket, causing data corruption and potentially leading to further security issues.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Linux Linux Kernel —
Siemens — —
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Threat Intelligence
● Threat Intelligence Validated: September 2026 | Threat Age: 62 Days
CISA KEV● Active Exploitation Confirmed (added 2026-09-18)
Public ExploitNot confirmed
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashd876e97e95caa64cd43dfc0c51ca959af20541faf9787721916b3e86979b154087f6064cf6ae73502a87016e0c104931ea2dd82ecbcfdc95e217b74b99bf0df0
Related CVEs affecting Linux
CVE-1999-0698 10.0 Denial of service in IP protocol logger (ippl) on Red Hat and Debian Linux. CVE-2009-0065 10.0 Buffer overflow in net/sctp/sm_statefuns.c in the Stream Control Transmission... CVE-2010-2298 10.0 browser/renderer_host/database_dispatcher_host.cc in Google Chrome before 5.0... CVE-2012-0751 10.0 The ActiveX control in Adobe Flash Player before 10.3.183.15 and 11.x before ... CVE-2011-3101 10.0 Google Chrome before 19.0.1084.46 on Linux does not properly mitigate an unsp...
View all Linux CVEs →

This Vulnerability Is Being Actively Exploited

CVE-2025-39964 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider flags known-exploited CVEs on the ICS assets they affect, with known-exploited status synced daily from CISA.

Create a free account →