AI description
CVE-2025-39964 describes a race condition vulnerability found within the Linux kernel's cryptographic user API, specifically affecting the `AF_ALG` component. This flaw arises from the way concurrent write operations to the same `AF_ALG` socket are managed. The vulnerability can lead to unpredictable interleaving of data and inconsistencies in the internal state of the socket. To address this, a fix was implemented that introduces an exclusive write ownership mechanism (`ctx->write`), ensuring that only one writer can issue `sendmsg()` at a time and preventing state corruption.
- Description
- In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
- NVD status
- Analyzed
- Products
- linux_kernel, simatic_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware, simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmware
CVSS 3.1
- Type
- Primary
- Base score
- 5.5
- Impact score
- 3.6
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Severity
- MEDIUM
Data from CISA
- Vulnerability name
- Linux Kernel Race Condition Vulnerability
- Exploit added on
- Sep 18, 2026
- Exploit action due
- Sep 21, 2026
- Required action
- Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
19
Kernel działa? To nie znaczy, że jest bezpieczny. CISA potwierdziła aktywne wykorzystanie 3 luk Linuxa: CVE-2025-39682, CVE-2026-53266 i CVE-2025-39964. Zaktualizuj kernel, zrestartuj host i sprawdź realną ekspozycję. #Linux #Security https://t.co/rvyG3KoBKn
@quietcodelife
20 Sept 2026
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA: Linux hosts have until tomorrow (Sep 21) to clear 3 actively exploited kernel bugs. CVE-2025-39682 — kTLS receive path CVE-2025-39964 — AF_ALG crypto race CVE-2026-53266 — ebtables SNAT (Dirty-Pipe-family) All on KEV. Forensic triage required.
@Sunil_kumawat17
20 Sept 2026
26 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
⚠️ Linux : CISA ajoute 3 failles du kernel activement exploitées au catalogue KEV : CVE-2025-39682, CVE-2026-53266 et CVE-2025-39964. Détails d’exploitation encore limités. Vérifiez vos noyaux et appliquez les correctifs distro en priorité. #Cyber #Linux
@TwitGri
20 Sept 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
News: CISA added 3 Linux kernel flaws to KEV. Attackers exploit CVE-2025-39682 (9.8), CVE-2026-53266, and CVE-2025-39964. Patch kernels now. Hunt local privilege jumps. US federal deadline is 21 Sept. https://t.co/qJc3OgOtZr
@snakeyesV1
20 Sept 2026
126 Impressions
1 Retweet
1 Like
0 Bookmarks
0 Replies
1 Quote
PCMedicalist Signal · Sep 19 CVE-2025-39964 is now in CISA KEV--Linux Kernel Race Condition, a privileged function with no auth in front of it. We've built agent systems and on-chain infrastructure on Blue-Team discipline for 17 years. PCMedicalist · https://t.co/FgdnzXrZws
@PCMedicalist
20 Sept 2026
25 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🔐 Daily Security & Standards Brief (Sep 19) CVE-2025-39964--Linux Kernel Race Condition: patch Linux Kernel Race Condition and verify the fix held. Full digest 👇 via PCMedicalist #CyberSecurity #InfoSec https://t.co/q8XoOSKDCC
@PCMedicalist
20 Sept 2026
28 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
@CISAgov adds three actively exploited Linux Kernel flaws to the KEV catalog. CVE-2025-39682 affects kTLS zero-length record handling. CVE-2026-53266 triggers an out-of-bounds write in ebtables ARP processing. CVE-2025-39964 is a race condition in AF_ALG sockets. Patch
@WorldCyberNewsX
20 Sept 2026
3 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
PCMedicalist Signal · Sep 19 CVE-2025-39964 is now in CISA KEV--Linux Kernel Race Condition, a privileged function with no auth in front of it. We've built agent systems and on-chain infrastructure on Blue-Team discipline for 17 years. PCMedicalist · https://t.co/FgdnzXrZws
@PCMedicalist
19 Sept 2026
39 Impressions
0 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
TRC analysis shows attackers are chaining three Linux kernel exploits (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) for privilege escalation and lateral movement across containerized workloads. Runtime segmentation helps contain post-compromise activity in these scenarios.
@aviatrixtrc
19 Sept 2026
55 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 ROOT ON YOUR LINUX BOXES: Check your kernels right now. CISA just threw multiple Linux privilege escalation bugs (CVE-2026-53266, CVE-2025-39964, CVE-2025-39682) into the Known Exploited Vulnerabilities catalog under emergency mandates. What’s happening? Attackers who h
@reach2ratan
19 Sept 2026
641 Impressions
15 Retweets
26 Likes
10 Bookmarks
0 Replies
0 Quotes
🔐 Daily Security & Standards Brief (Sep 19) CVE-2025-39964--Linux Kernel Race Condition: patch Linux Kernel Race Condition and verify the fix held. Full digest 👇 via PCMedicalist #CyberSecurity #InfoSec https://t.co/fXMHM73Gii
@PCMedicalist
19 Sept 2026
34 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA incluiu 3 falhas do Kernel Linux no KEV: CVE-2025-39682, CVE-2026-53266 e CVE-2025-39964. Há exploração ativa confirmada. Priorize patches em infraestrutura crítica e cloud. https://t.co/1WXKxIiZdW https://t.co/eJQmiyvUfQ
@luizlcsec
19 Sept 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Three Linux kernel vulnerabilities. All confirmed exploited by CISA on the same day. CVE-2025-39682 (CVSS 9.8): a remotely triggerable flaw in the TLS receive path. CVE-2026-53266 (8.8): an out-of-bounds write in netfilter's ebtables ARP rewrite. CVE-2025-39964 (7.8): a race htt
@vuln_tracker
19 Sept 2026
293 Impressions
0 Retweets
6 Likes
0 Bookmarks
0 Replies
0 Quotes
Linux Kernel Race Condition (CVE-2025-39964): AF_ALG Socket Analysis CVE-2025-39964 is a high-severity race condition in the Linux Kernel's AF_ALG socket subsystem that allows local unprivileged memory… Full write-up → link in bio #cybersecurity #infosec #cve #kev #linux ht
@HotaSamit
19 Sept 2026
27 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA added 3 Linux kernel flaws to KEV: CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964. Red Hat confirms public exploits exist. Patch host kernels immediately. Source: https://t.co/OrlDmJvsEr Intel: https://t.co/QC14eBVf0C #2workly
@2Workly
19 Sept 2026
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Three severe Linux kernel vulnerabilities—CVE-2025-39682, CVE-2026-53266 & CVE-2025-39964—are now confirmed exploited in the wild. Red Hat’s advisories are live. US agencies face a patch deadline of September 21 under CISA’s KEV and BOD-26-04 mandates. Threats span pr
@dailytechonx
19 Sept 2026
61 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA put 3 Linux kernel flaws on KEV yesterday—actively exploited. Federal due: Sep 21. CVE-2025-39682 (TLS zero-length rx_list), CVE-2026-53266 (ebtables SNAT ARP → OOB write), CVE-2025-39964 (AF_ALG race). Linux self-hosters/cloud VMs: update weekend, not “wait for LTS
@Sunil_kumawat17
19 Sept 2026
73 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
【Linux更新、期限は9月21日】 ・CVE-2025-39964をKEV追加 ・Linux Kernelの競合状態 ・対応期限は2026年9月21日 既知悪用として期限付き対応です。 #CISA https://t.co/kgqphczd0u
@eng_digest_jp
19 Sept 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに2件と1件の脆弱性を追加。全てLinuxカーネルで、CVE-2025-39964、CVE-2026-53266、CVE-2025-39682。対処期限は3日後の9/21。ランサ
@__kokumoto
19 Sept 2026
1185 Impressions
1 Retweet
6 Likes
7 Bookmarks
2 Replies
0 Quotes
CISA put two Linux Kernel bugs on KEV today (CVE-2025-39964, CVE-2026-53266). Active exploitation. Federal due Sep 21. They hit every Linux fleet — VMs, NAS, firewalls, containers. Patch or rebuild, then check for prior compromise. https://t.co/ipqh8oJ6Q5
@bluefortit
19 Sept 2026
4 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CISA adds two actively exploited Linux Kernel vulnerabilities (CVE-2025-39964 & CVE-2026-53266) to the KEV Catalog. Federal agencies must prioritize patching these threats under BOD 26-04. Stay ahead with SOC Minute updates. #CISA #LinuxKernel #PatchManagement https://t.co/Pf
@SOCMinute
18 Sept 2026
34 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
CISA put two Linux kernel bugs on KEV today: CVE-2025-39964 (af_alg concurrent-write race) and CVE-2026-53266 (ebt_snat ARP rewrite on bridge netfilter). Already exploited — not a theoretical advisory pile. If your fleet still treats kernel updates like quarterly hygiene, thes
@Chris_L_Elliott
18 Sept 2026
51 Impressions
0 Retweets
1 Like
0 Bookmarks
1 Reply
0 Quotes
News: CISA put Linux kernel CVE-2025-39964 (AF_ALG race) and CVE-2026-53266 (ebtables SNAT write) on KEV Sep 18. Hits unpatched Linux hosts; both under active use. Apply your distro kernel update now; if stuck, blacklist af_alg and drop ebtables ARP rewrite.
@snakeyesV1
18 Sept 2026
73 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2025-39964 — HIGH — actively exploited per CISA KEV Linux Kernel CVSS 7.8 | EPSS 0% #Linux #CVE https://t.co/HCBvsDdAyZ
@threatpodium
18 Sept 2026
1 Impression
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Linux kernel CISA KEV (today): CVE-2025-39964 and CVE-2026-53266. AF_ALG race condition and out-of-bounds write. CISA cites active exploitation evidence. Patch or roll vendor kernel updates across managed Linux fleets now. #CVE #KEV
@HoustonIntrove1
18 Sept 2026
32 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CISA KEV Alert: CVE-2025-39964 and CVE-2026-53266 Linux Kernel Exploits — Detec… "On September 18, 2026, CISA added two Linux kernel vulnerabilities to its Known Exploited…" 🔗 https://t.co/J5PKZ0z0Ml #CyberSecurity #ThreatIntel #critical #zeroday
@SecurityAr58409
18 Sept 2026
39 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
TRC analysis shows attackers exploiting Linux kernel vulnerabilities CVE-2025-39964 and CVE-2026-53266 to gain root privileges and move laterally across network segments. Runtime segmentation helps contain post-compromise activity when kernel-level access is achieved. #ZeroTrust
@aviatrixtrc
18 Sept 2026
57 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
【緊急】Linuxカーネルに悪用確認済みの脆弱性2件(CVE-2025-39964 / CVE-2026-53266) CISAが9/18にKEV追加、期限は9/21。 対処: ディストリのトラッカーで自分の版が修正済みかを確認し、更新して再起動。 https://t.co/6Gqy
@ForsmileDNet
18 Sept 2026
7 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🔒 #CyberSecurity CVE-2025-39964: Linux Kernel AF_ALG Race Condition Added to CISA KEV — Detectio… "On September 18, 2026, CISA added CVE-2025-39964 to its Known Exploited…" 🔗 https://t.co/k21wXoegIL #CyberSecurity #ThreatIntel #cve202539964 #critical #cisakev
@SecurityAr58409
18 Sept 2026
38 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
⚠️ ACTIVELY EXPLOITED — added to CISA KEV 2026-09-18 CVE-2025-39964: Linux Kernel Race Condition Vulnerability CVSS 7.8 · EPSS 0.3% · 2 public exploits Details, versions & intel → https://t.co/mu0kiVk9QK https://t.co/ASAweorZv1
@notCVE
18 Sept 2026
47 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
🛡 We added Linux Kernal race condition vulnerability CVE-2025-39964 & out-of-bounds write vulnerability CVE-2026-53266 to our KEV Catalog. Visit https://t.co/myxOwap1Tf & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/SpBC
@CISACyber
18 Sept 2026
6155 Impressions
4 Retweets
19 Likes
5 Bookmarks
1 Reply
0 Quotes
🔴 CISA Adds Two Linux Kernel Vulnerabilities to Known Exploited List CISA added CVE-2025-39964 (Linux kernel race condition) and CVE-2026-53266 (Linux kernel out-of-bounds write) to its Known Exploited Vulnerabilities Catalog based on active exploitation evidence. Binding htt
@NewsTongueX
18 Sept 2026
43 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CISA ADDS TWO LINUX KERNEL VULNS TO KEV CATALOG CISA has added two Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation (catalog date 2026-09-18). CVEs added: • CVE-2025-39964 — race condition (AF_ALG sock
@DailyDarkWeb
18 Sept 2026
5037 Impressions
0 Retweets
5 Likes
2 Bookmarks
1 Reply
0 Quotes
CVE-2025-39964 In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_… https://t.co/SiXeg0E0nM
@CVEnew
13 Oct 2025
346 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "EC314BAD-D810-4C02-ABB3-11D90E06AEAA",
"versionEndExcluding": "5.10.245",
"versionStartIncluding": "2.6.38",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "CF862263-DC8D-4324-A52A-DA1D7880B35A",
"versionEndExcluding": "5.15.194",
"versionStartIncluding": "5.11",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "E49CD91E-FC55-45B0-BB63-9AD5F5D70CAA",
"versionEndExcluding": "6.1.154",
"versionStartIncluding": "5.16",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A7E8EAEE-7731-4996-9578-696255D61EA2",
"versionEndExcluding": "6.6.108",
"versionStartIncluding": "6.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "CAA033E9-A2C5-4976-A83E-9804D8FB827F",
"versionEndExcluding": "6.12.49",
"versionStartIncluding": "6.7",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"matchCriteriaId": "638DD910-1189-4F5E-98BF-2D436B695112",
"versionEndExcluding": "6.16.9",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*",
"matchCriteriaId": "327D22EF-390B-454C-BD31-2ED23C998A1C",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:*",
"matchCriteriaId": "C730CD9A-D969-4A8E-9522-162AAF7C0EE9",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:*",
"matchCriteriaId": "39982C4B-716E-4B2F-8196-FA301F47807D",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:*",
"matchCriteriaId": "340BEEA9-D70D-4290-B502-FBB1032353B1",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc5:*:*:*:*:*:*",
"matchCriteriaId": "47E4C5C0-079F-4838-971B-8C503D48FCC2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:6.17:rc6:*:*:*:*:*:*",
"matchCriteriaId": "5A4516A6-C12E-42A4-8C0E-68AEF3264504",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "421F0D66-BEED-4A31-801A-D4414D790123",
"versionStartIncluding": "3.1.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
"matchCriteriaId": "7F223390-56E5-4F1F-A4BE-E96003F7BDC3",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp_firmware:*:*:*:*:*:*:*:*",
"matchCriteriaId": "1B9AA936-AF22-46C2-B6BC-0DD8FD6A0309",
"versionStartIncluding": "3.1.6",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
},
{
"cpeMatch": [
{
"criteria": "cpe:2.3:h:siemens:simatic_s7-1500_cpu_1518f-4_pn\\/dp_mfp:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6DD481CC-4EC9-4248-943E-3AD5F79277B2",
"vulnerable": false
}
],
"negate": false,
"operator": "OR"
}
],
"operator": "AND"
}
]