Concurrent Writes Vulnerability in Linux Kernel Affecting Socket Operations
CVE-2025-39964

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
13 October 2025

Badges

📈 Score: 474👾 Exploit Exists🦅 CISA Reported📰 News Worthy

What is CVE-2025-39964?

CVE-2025-39964 is a vulnerability found in the Linux kernel, specifically associated with socket operations via the af_alg interface used for cryptographic algorithms. This vulnerability arises from the improper handling of concurrent write operations to the same af_alg socket. When multiple write requests are made simultaneously, it can lead to unpredictable data interleaving and inconsistencies within the internal socket state. This flaw endangers the reliability and integrity of applications relying on cryptographic functionalities, as it disrupts the expected behavior of data transmission within the kernel.

The implications of this vulnerability are concerning for organizations as it threatens the secure handling of sensitive data, particularly in environments reliant on secure communication protocols. Failure to address this vulnerability could facilitate data corruption or mismanagement, potentially leading to severe impacts including security breaches and compromised operational processes.

Potential impact of CVE-2025-39964

  1. Data Integrity Risks: The vulnerability can cause unpredictable behavior during socket operations, leading to corrupted data transmissions and unpredictable results in applications that depend on cryptographic operations.

  2. Application Instability: Applications utilizing the affected socket interface may experience crashes or unexpected behavior, which could disrupt business operations and affect service availability.

  3. Security Compromises: Exploitation of this vulnerability could allow malicious actors to manipulate or intercept sensitive data, thereby creating opportunities for further attacks or data breaches within the organization's infrastructure.

CISA has reported CVE-2025-39964

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2025-39964 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected Version(s)

Linux 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 < 0f28c4adbc4a97437874c9b669fd7958a8c6d6ce

Linux 8ff590903d5fc7f5a0a988c38267a3d08e6393a2

Linux 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 < 1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8

News Articles

CISA alerts of active exploitation of three Linux kernel flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical.

1 hour ago

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 📰

    First article discovered by BleepingComputer

  • 👾

    Exploit known to exist

  • 🦅

    CISA Reported

  • Vulnerability published

  • Vulnerability Reserved

.