
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-39964 is a vulnerability discovered in the Linux kernel's AF_ALG socket implementation, disclosed on October 13, 2025. The vulnerability affects the crypto subsystem's af_alg component, specifically in the af_alg_sendmsg functionality (NVD).
The vulnerability stems from a design flaw in the AF_ALG datapath that allows concurrent writes to the same socket. When two writes occur simultaneously to the same af_alg socket, the data becomes interleaved unpredictably, leading to inconsistencies in the internal socket state. The issue has been assigned a CVSS 3.1 Base Score of 5.5 (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H), indicating moderate severity (Red Hat).
The vulnerability can result in unpredictable data interleaving and corruption of the socket's internal state when multiple processes attempt to write to the same AF_ALG socket simultaneously. This can potentially lead to system instability and denial of service conditions (NVD).
The vulnerability requires local access and can be triggered by issuing concurrent writes to the same af_alg socket. While the attack complexity is low, it requires local user privileges to exploit (Red Hat).
A fix has been implemented by adding a new ctx->write field that indicates exclusive ownership for writing, preventing concurrent writes to the same socket. As a temporary workaround, systems can prevent the af_alg module from being loaded. Red Hat recommends blacklisting the kernel module to prevent it from loading automatically (Red Hat).
Fix availability across major Linux distributions and their releases.
bionic (esm-infra)
linux: 4.15.0-245.257
bionic (fips-updates)
linux-fips: 4.15.0-1142.154
bionic (fips)
linux-fips
devel
linux
focal
linux-azure-fde-5.15
focal (esm-infra)
linux: 5.4.0-224.244
focal (fips-updates)
linux-fips: 5.4.0-1127.137
focal (fips)
linux-fips
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."