CVE-2025-39964
Description
In the Linux kernel, the following vulnerability has been resolved:
crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
Issuing two writes to the same af_alg socket is bogus as the
data will be interleaved in an unpredictable fashion. Furthermore,
concurrent writes may create inconsistencies in the internal
socket state.
Disallow this by adding a new ctx->write field that indiciates
exclusive ownership for writing.
Summary dbcve.org
Race condition in Linux kernel's AF_ALG crypto socket interface allows concurrent write operations to corrupt data and internal state. Two simultaneous writes to the same af_alg socket interleave data unpredictably and create inconsistencies. The fix adds a ctx->write flag to enforce exclusive write ownership.
Mitigation
Apply the kernel patch which adds exclusive ownership tracking for writes. Avoid concurrent write operations to af_alg sockets until patched.