MEDIUM

CVE-2025-39964

Linux Linux Kernel 2025-10-13 CVSS v3.1
CVSS
5.5
KEV

Description

In the Linux kernel, the following vulnerability has been resolved:

crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg

Issuing two writes to the same af_alg socket is bogus as the
data will be interleaved in an unpredictable fashion. Furthermore,
concurrent writes may create inconsistencies in the internal
socket state.

Disallow this by adding a new ctx->write field that indiciates
exclusive ownership for writing.

Summary dbcve.org

Race condition in Linux kernel's AF_ALG crypto socket interface allows concurrent write operations to corrupt data and internal state. Two simultaneous writes to the same af_alg socket interleave data unpredictably and create inconsistencies. The fix adds a ctx->write flag to enforce exclusive write ownership.

Mitigation

Apply the kernel patch which adds exclusive ownership tracking for writes. Avoid concurrent write operations to af_alg sockets until patched.

Patch Commit

Weakness (CWE)

CWE-362 Race Condition

EPSS Score

0.79%
Probability of exploitation in next 30 days
54.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE