CVE-2025-39964
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.
Yes
CISA added it 2026-09-18. An observation, not a forecast.
0%
Chance of exploitation in the next 30 days, 25th percentile of all CVEs. A forecast; KEV outranks it.
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
—
No exposure census on this CVE's dispatches.
No dispatch on our wire has named this CVE yet.
- nvd.nist.gov ↗
- cisa.gov · KEV catalogue ↗
- first.org · EPSS ↗
- git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce ↗
- git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285 ↗
- git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8 ↗
- git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042 ↗
- git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84 ↗
Watch this one?
Early access opens alerts first — one email when a CVE you follow lands on KEV or an adversary you follow lands on the wire. Nothing else, ever.