VYPR
High severity7.8CISA KEVNVD Advisory· Published Oct 13, 2025· Updated Sep 19, 2026

CVE-2025-39964

CVE-2025-39964

Description

In the Linux kernel, the following vulnerability has been resolved:

crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg

Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state.

Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

191

Patches

Vulnerability mechanics

References

9

News mentions

7