Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2025-39964
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-39964 is a vulnerability discovered in the Linux kernel's AF_ALG socket implementation, disclosed on October 13, 2025. The vulnerability affects the crypto subsystem's af_alg component, specifically in the af_alg_sendmsg functionality (NVD).

Technical details

The vulnerability stems from a design flaw in the AF_ALG datapath that allows concurrent writes to the same socket. When two writes occur simultaneously to the same af_alg socket, the data becomes interleaved unpredictably, leading to inconsistencies in the internal socket state. The issue has been assigned a CVSS 3.1 Base Score of 5.5 (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H), indicating moderate severity (Red Hat).

Impact

The vulnerability can result in unpredictable data interleaving and corruption of the socket's internal state when multiple processes attempt to write to the same AF_ALG socket simultaneously. This can potentially lead to system instability and denial of service conditions (NVD).

Exploitability

The vulnerability requires local access and can be triggered by issuing concurrent writes to the same af_alg socket. While the attack complexity is low, it requires local user privileges to exploit (Red Hat).

Mitigation and workarounds

A fix has been implemented by adding a new ctx->write field that indicates exclusive ownership for writing, preventing concurrent writes to the same socket. As a temporary workaround, systems can prevent the af_alg module from being loaded. Red Hat recommends blacklisting the kernel module to prevent it from loading automatically (Red Hat).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

linux: 6.1.158-1

Fixed

sid

linux: 6.16.9-1

Fixed

trixie

linux: 6.12.57-1

Fixed

Ubuntu

Fixed

bionic (esm-infra)

linux: 4.15.0-245.257

Fixed

bionic (fips-updates)

linux-fips: 4.15.0-1142.154

Fixed

bionic (fips)

linux-fips

Affected

devel

linux

Not Affected

focal

linux-azure-fde-5.15

Not Affected

focal (esm-infra)

linux: 5.4.0-224.244

Fixed

focal (fips-updates)

linux-fips: 5.4.0-1127.137

Fixed

focal (fips)

linux-fips

Affected

RHEL / CentOS

Affected

RHEL 8

kernel.src

Affected

RHEL 9

kernel-rt.src

Affected

RHEL 10

kernel.src

Affected

SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93189HIGH8.8
  • Linux Kernel logoLinux Kernel
  • kernel
NoYesSep 17, 2026
CVE-2026-93188MEDIUM6.5
  • Linux Kernel logoLinux Kernel
  • linux-azure-5.4
NoYesSep 17, 2026
CVE-2026-93182NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-5.4
NoYesSep 17, 2026
CVE-2026-93181NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-lowlatency
NoNoSep 17, 2026
CVE-2026-93174NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-azure-6.17
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management