PT-2025-41786 · Linux+3 · Linux Kernel+3

Published

2025-09-16

·

Updated

2026-04-20

·

CVE-2025-39964

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The Linux kernel contains an issue in the crypto/af alg module where concurrent writes to the same af alg socket can lead to data interleaving and inconsistencies in the internal socket state. This occurs because multiple write operations to the same socket are not permitted, as they can result in unpredictable data mixing and potential corruption of the socket's internal state. The issue is addressed by introducing a ctx->write field to indicate exclusive ownership for writing.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Weakness Enumeration

Related Identifiers

AZL-68460
AZL-76437
BDU:2025-16058
CVE-2025-39964
DLA-4379-1
DLA-4404-1
DSA-6053-1
ECHO-F6FA-E508-7A91
MGASA-2025-0309
MGASA-2025-0310
OESA-2025-2765
OESA-2025-2766
OESA-2025-2767
OESA-2025-2768
OPENSUSE-SU-2026:20416-1
SUSE-SU-2026:0962-1
SUSE-SU-2026:1041-1
SUSE-SU-2026:1078-1
SUSE-SU-2026:1081-1
SUSE-SU-2026:20667-1
SUSE-SU-2026:20720-1
SUSE-SU-2026:20838-1
SUSE-SU-2026:20845-1
SUSE-SU-2026:20876-1
SUSE-SU-2026:20931-1
SUSE-SU-2026:21284-1
USN-7907-1
USN-7907-2
USN-7907-3
USN-7907-4
USN-7907-5
USN-7921-1
USN-7921-2
USN-7922-1
USN-7922-2
USN-7922-3
USN-7922-4
USN-7922-5
USN-7928-1
USN-7928-2
USN-7928-3
USN-7928-4
USN-7928-5
USN-7930-1
USN-7930-2
USN-7931-1
USN-7931-2
USN-7931-3
USN-7931-4
USN-7931-5
USN-7934-1
USN-7935-1
USN-7936-1
USN-7937-1
USN-7938-1
USN-7939-1
USN-7939-2
USN-7940-1
USN-7940-2

Affected Products

Debian
Linuxmint
Linux Kernel
Ubuntu