Skip to content
feed: live
>_0dayNews
CVE Record
[ HIGH ]CVE-2025-39964

Linux Kernel Race Condition Vulnerability

Linux kernel AF_ALG race condition: concurrent writes corrupt state, crashing the system or corrupting cryptographic output. CVSS 7.8. CISA KEV Sept. 18.

cat cve-2025-39964.json
Vendor
Linux
Product
Kernel
CVSS
7.8
EPSS (exploit probability)
0.3%
Status
kev
CISA patch-by (BOD 22-01)
Published

Race condition in AF_ALG (the Linux kernel’s crypto interface) socket operations. When two concurrent writes target the same AF_ALG socket, the data they send interleaves unpredictably and leaves the socket’s internal state inconsistent. The result can be a system crash or corrupted cryptographic output.

CISA added this to the Known Exploited Vulnerabilities catalog on September 18, 2026 with active exploitation confirmed. Federal agencies have until September 21, 2026 under BOD 26-04. NVD notes affected versions may include end-of-life kernel releases. See the NVD record and your distribution vendor’s advisories for version details.

Full coverage: CISA Adds Three Exploited Linux Kernel Flaws to KEV.