CVE-2025-39964: Linux Kernel Race Condition Vulnerability
crypto: afalg - Disallow concurrent writes in afalgsendmsg
Other sources
Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AFALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39964?
CVE-2025-39964 has been classified with a medium severity rating due to its potential impact on data integrity.
How do I fix CVE-2025-39964?
To resolve CVE-2025-39964, ensure your Linux kernel is updated to the latest version where the vulnerability has been patched.
What systems are affected by CVE-2025-39964?
CVE-2025-39964 affects the Linux kernel, specifically systems utilizing the af_alg socket for crypto operations.
What are the risks of not addressing CVE-2025-39964?
Failing to address CVE-2025-39964 may lead to data corruption due to unpredictable interleaving of concurrent write operations.
When was CVE-2025-39964 reported?
CVE-2025-39964 was reported in 2025, highlighting a concern regarding concurrent write handling in the Linux kernel.