THREAT OPS › CVEs › CVE-2025-39964
CVE-2025-39964 — Linux Kernel Race Condition Vulnerability
Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.
Vulnerability details
- Affected productsKernel
- KEV remediation due2026-09-21
Related reporting
- CISA Adds Two Known Exploited Vulnerabilities to Catalogcisa_advisories
- [CISA KEV] CVE-2025-39964 — Linux Kernel: Linux Kernel Race Condition Vulnerabilitycisa_kev
- [NVD] CVE-2025-39964 (HIGH 7.8) — In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes mnvd
- Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFPcisa_ics
- Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFPcisa_advisories