DIRAS TAKE
Urgent: CISA added this CVE to its Known Exploited Vulnerabilities catalog on 2026-09-18 with a remediation deadline of 2026-09-21, so prioritize applying fixes or mitigations immediately.
What is CVE-2025-39964?
Local attackers can trigger a race by performing simultaneous write operations to the same AF_ALG socket, which may cause data from separate writes to mix unpredictably and leave the socket in an inconsistent state, risking confidentiality, integrity, and availability. CVE-2025-39964 affects multiple Linux kernel branches with fixes committed for several lines (see affected[] for commit IDs); the 2.x branch entry lists version 2.6.38 without a provided fix. Exploitation requires local ability to open and write to AF_ALG sockets; no user interaction or network access is needed.
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Linux Kernel are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 0.x | 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 – before 0f28c4adbc4a97437874c9b669fd7958a8c6d6ce | 0f28c4adbc4a97437874c9b669fd7958a8c6d6ce |
| Linux | 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 – before e4c1ec11132ec466f7362a95f36a506ce4dc08c9 | e4c1ec11132ec466f7362a95f36a506ce4dc08c9 |
| 1.x | 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 – before 1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8 | 1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8 |
| 7.x | 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 – before 7c4491b5644e3a3708f3dbd7591be0a570135b84 | 7c4491b5644e3a3708f3dbd7591be0a570135b84 |
| 9.x | 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 – before 9aee87da5572b3a14075f501752e209801160d3d | 9aee87da5572b3a14075f501752e209801160d3d |
| 45.x | 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 – before 45bcf60fe49b37daab1acee57b27211ad1574042 | 45bcf60fe49b37daab1acee57b27211ad1574042 |
| 1.x | 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 – before 1b34cbbf4f011a121ef7b2d7d6e6920a036d5285 | 1b34cbbf4f011a121ef7b2d7d6e6920a036d5285 |
| 2.x | 2.6.38 |
Is CVE-2025-39964 being exploited?
CISA added CVE-2025-39964 to the Known Exploited Vulnerabilities catalog on 2026-09-18; US federal agencies were required to remediate by 2026-09-21.
How to fix CVE-2025-39964
- Apply vendor or distribution kernel updates that include the listed fixes (install kernels containing the referenced commit IDs for your branch).
- If a patched kernel is unavailable for your specific build (noting 2.6.38 lists no fix), limit who can create or write to AF_ALG sockets and isolate at-risk systems from untrusted local users.
- Enable monitoring for AF_ALG socket creation and concurrent write attempts and follow vendor guidance for triage and forensic collection.
Frequently asked questions
Is CVE-2025-39964 being actively exploited?
CISA added CVE-2025-39964 to its Known Exploited Vulnerabilities catalog on 2026-09-18; remediation was mandated by 2026-09-21 for federal agencies.
Which Linux Kernel versions are affected by CVE-2025-39964?
Several kernel branches are listed as affected: mainline/Linux and branches labeled 0.x, 1.x, 7.x, 9.x, and 45.x are affected up to the commit IDs that contain fixes; branch 2.x (2.6.38) is identified without a provided fix.
Is there a patch for CVE-2025-39964?
Yes. Patches exist and are recorded as specific commit IDs for the affected branches; apply the appropriate vendor or distribution updates that include those commits.
Does CVE-2025-39964 require authentication?
The issue does not require network authentication; it requires local capability to open and write to AF_ALG sockets, so an attacker or process with local access is necessary.
References
- nvd.nist.gov/vuln/detail/CVE-2025-39964
- cve.org/CVERecord?id=CVE-2025-39964
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-39964
- git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce
- git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9
- git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8
- git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84
- git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d
- git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042
- git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285
- All Linux CVEs on CVE Radar
- CVEs published in September 2026