Linux Kernel Race Condition Vulnerability
Linux kernel AF_ALG race condition: concurrent writes corrupt state, crashing the system or corrupting cryptographic output. CVSS 7.8. CISA KEV Sept. 18.
- Vendor
- Linux
- Product
- Kernel
- CVSS
- 7.8
- EPSS (exploit probability)
- 0.3%
- Status
- kev
- CISA patch-by (BOD 22-01)
- Published
Race condition in AF_ALG (the Linux kernel’s crypto interface) socket operations. When two concurrent writes target the same AF_ALG socket, the data they send interleaves unpredictably and leaves the socket’s internal state inconsistent. The result can be a system crash or corrupted cryptographic output.
CISA added this to the Known Exploited Vulnerabilities catalog on September 18, 2026 with active exploitation confirmed. Federal agencies have until September 21, 2026 under BOD 26-04. NVD notes affected versions may include end-of-life kernel releases. See the NVD record and your distribution vendor’s advisories for version details.
Full coverage: CISA Adds Three Exploited Linux Kernel Flaws to KEV.
