CVE-2025-39964
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data...
Affects 1 product across 2 vendors.
Software behavior depends on event timing that is not enforced, allowing attackers to exploit the timing window.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
A vulnerability in the Linux kernel's crypto: af_alg module allows for concurrent writes to the same af_alg socket, leading to data interleaving and potential inconsistencies in the internal socket state.
BSID: BS-2025-GLOBAL-269863-L • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2025-39964?
What is the CVSS score for CVE-2025-39964?
Is CVE-2025-39964 actively exploited?
How do I remediate CVE-2025-39964?
What systems are affected by CVE-2025-39964?
| CVE ID | CVE-2025-39964 |
|---|---|
| BSID | BS-2025-GLOBAL-269863-L BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
| Published | 2026-07-28 |
| Last Modified | 2026-09-19 |
| ICS Relevance | 85% |
| Weakness (CWE) | |
| Source | NVD |
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.
Source: NIST NVD / MITRE CVE Database
An attacker could exploit this vulnerability by issuing concurrent writes to the same af_alg socket, causing data corruption and potentially leading to further security issues.
Exploitation Likelihood: MEDIUM
| CISA KEV | ● Active Exploitation Confirmed (added 2026-09-18) |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
AI Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | d876e97e95caa64cd43dfc0c51ca959af20541faf9787721916b3e86979b154087f6064cf6ae73502a87016e0c104931ea2dd82ecbcfdc95e217b74b99bf0df0 |
This Vulnerability Is Being Actively Exploited
CVE-2025-39964 is on the CISA KEV list - confirmed active exploitation in the wild. BreachSpider flags known-exploited CVEs on the ICS assets they affect, with known-exploited status synced daily from CISA.
Create a free account →