Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2025-39964

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 54.7%
CVSS Severity
CVSS v3 Score 7.8
Proposed Action
Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.
Ransomware Campaign
Unknown
Products affected by CVE-2025-39964


Contact Us

Shodan ® - All rights reserved