CVE-2025-39964: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
Published Oct 13, 2025
·Updated
crypto: afalg - Disallow concurrent writes in afalgsendmsg
Affected Software
15 affected componentsFixes available
Linux Linux kernel
Microsoft azl3 kernel 6.6.96.2-2
Microsoft azl3 kernel 6.6.104.2-4
Linux Linux kernel>=2.6.38<5.10.245
Linux Linux kernel>=5.11<5.15.194
Linux Linux kernel>=5.16<6.1.154
Linux Linux kernel>=6.2<6.6.108
Linux Linux kernel>=6.7<6.12.49
Linux Linux kernel>=6.13<6.16.9
Linux Linux kernel=6.17-rc1
Linux Linux kernel=6.17-rc2
Linux Linux kernel=6.17-rc3
Linux Linux kernel=6.17-rc4
Linux Linux kernel=6.17-rc5
Linux Linux kernel=6.17-rc6
Event History
Oct 13, 2025
CVE Published
via MITRE·01:48 PM
Data Sourced
via MITRE·01:48 PM
DescriptionSeverity
Data Sourced
via NVD·02:15 PM
RemedyDescriptionSeverityAffected Software
Oct 15, 2025
Data Sourced
via Microsoft·01:01 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·01:01 AM
Affected Software
Updated
via Microsoft·01:01 AM
DescriptionSeverity
Updated
via Microsoft·01:01 AM
Affected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-39964?
CVE-2025-39964 has been classified with a medium severity rating due to its potential impact on data integrity.
2
How do I fix CVE-2025-39964?
To resolve CVE-2025-39964, ensure your Linux kernel is updated to the latest version where the vulnerability has been patched.
3
What systems are affected by CVE-2025-39964?
CVE-2025-39964 affects the Linux kernel, specifically systems utilizing the af_alg socket for crypto operations.
4
What are the risks of not addressing CVE-2025-39964?
Failing to address CVE-2025-39964 may lead to data corruption due to unpredictable interleaving of concurrent write operations.
5
When was CVE-2025-39964 reported?
CVE-2025-39964 was reported in 2025, highlighting a concern regarding concurrent write handling in the Linux kernel.