• CISA KEV
  • EXPLOITED
  • PoC PUBLIC
  • PATCH AVAILABLE

CVE-2025-39964: local race condition in Linux Kernel

Local attackers can trigger a race by performing simultaneous write operations to the same AF_ALG socket, which may cause data from separate writes to mix unpredictably and leave the socket in an inconsistent state, risking confidentiality, integrity, and availability. CVE-2025-39964 affects multiple Linux kernel branches with fixes committed for several lines (see affected[] for commit IDs); the 2.x branch entry lists version 2.6.38 without a provided fix. Exploitation requires local ability to open and write to AF_ALG sockets; no user interaction or network access is needed.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS

CVSS 3.1
7.8HIGH
EPSS
0.00996
CWE
KEV DUE DATE
PATCH
Available

DIRAS TAKE

Urgent: CISA added this CVE to its Known Exploited Vulnerabilities catalog on 2026-09-18 with a remediation deadline of 2026-09-21, so prioritize applying fixes or mitigations immediately.

What is CVE-2025-39964?

Local attackers can trigger a race by performing simultaneous write operations to the same AF_ALG socket, which may cause data from separate writes to mix unpredictably and leave the socket in an inconsistent state, risking confidentiality, integrity, and availability. CVE-2025-39964 affects multiple Linux kernel branches with fixes committed for several lines (see affected[] for commit IDs); the 2.x branch entry lists version 2.6.38 without a provided fix. Exploitation requires local ability to open and write to AF_ALG sockets; no user interaction or network access is needed.

Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Linux Kernel are affected?

BRANCHAFFECTEDFIXED
0.x8ff590903d5fc7f5a0a988c38267a3d08e6393a2 – before 0f28c4adbc4a97437874c9b669fd7958a8c6d6ce0f28c4adbc4a97437874c9b669fd7958a8c6d6ce
Linux8ff590903d5fc7f5a0a988c38267a3d08e6393a2 – before e4c1ec11132ec466f7362a95f36a506ce4dc08c9e4c1ec11132ec466f7362a95f36a506ce4dc08c9
1.x8ff590903d5fc7f5a0a988c38267a3d08e6393a2 – before 1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c81f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8
7.x8ff590903d5fc7f5a0a988c38267a3d08e6393a2 – before 7c4491b5644e3a3708f3dbd7591be0a570135b847c4491b5644e3a3708f3dbd7591be0a570135b84
9.x8ff590903d5fc7f5a0a988c38267a3d08e6393a2 – before 9aee87da5572b3a14075f501752e209801160d3d9aee87da5572b3a14075f501752e209801160d3d
45.x8ff590903d5fc7f5a0a988c38267a3d08e6393a2 – before 45bcf60fe49b37daab1acee57b27211ad157404245bcf60fe49b37daab1acee57b27211ad1574042
1.x8ff590903d5fc7f5a0a988c38267a3d08e6393a2 – before 1b34cbbf4f011a121ef7b2d7d6e6920a036d52851b34cbbf4f011a121ef7b2d7d6e6920a036d5285
2.x2.6.38

Is CVE-2025-39964 being exploited?

CISA added CVE-2025-39964 to the Known Exploited Vulnerabilities catalog on 2026-09-18; US federal agencies were required to remediate by 2026-09-21.

How to fix CVE-2025-39964

  1. Apply vendor or distribution kernel updates that include the listed fixes (install kernels containing the referenced commit IDs for your branch).
  2. If a patched kernel is unavailable for your specific build (noting 2.6.38 lists no fix), limit who can create or write to AF_ALG sockets and isolate at-risk systems from untrusted local users.
  3. Enable monitoring for AF_ALG socket creation and concurrent write attempts and follow vendor guidance for triage and forensic collection.

Frequently asked questions

Is CVE-2025-39964 being actively exploited?

CISA added CVE-2025-39964 to its Known Exploited Vulnerabilities catalog on 2026-09-18; remediation was mandated by 2026-09-21 for federal agencies.

Which Linux Kernel versions are affected by CVE-2025-39964?

Several kernel branches are listed as affected: mainline/Linux and branches labeled 0.x, 1.x, 7.x, 9.x, and 45.x are affected up to the commit IDs that contain fixes; branch 2.x (2.6.38) is identified without a provided fix.

Is there a patch for CVE-2025-39964?

Yes. Patches exist and are recorded as specific commit IDs for the affected branches; apply the appropriate vendor or distribution updates that include those commits.

Does CVE-2025-39964 require authentication?

The issue does not require network authentication; it requires local capability to open and write to AF_ALG sockets, so an attacker or process with local access is necessary.

References