CVE-2025-39964: Linux Kernel Race Condition Vulnerability

Medium severity, CVSS 5.5. Actively exploited: in CISA KEV since 2026-09-18. EPSS: 1.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.

Affected products

  • Linux Linux Kernel: from 2.6.38, before 5.10.245 (fixed in 5.10.245); from 5.11, before 5.15.194 (fixed in 5.15.194); from 5.16, before 6.1.154 (fixed in 6.1.154); from 6.2, before 6.6.108 (fixed in 6.6.108); from 6.7, before 6.12.49 (fixed in 6.12.49); from 6.13, before 6.16.9 (fixed in 6.16.9); …
  • Siemens SIMATIC s7-1500 CPU 1518-4 Pn/dp Mfp Firmware: from 3.1.6
  • Siemens SIMATIC s7-1500 CPU 1518f-4 Pn/dp Mfp Firmware: from 3.1.6

Published 2025-10-13. Last modified 2026-09-19.