IM
IronMonkey Threat Research

CVE-2025-39964 HIGH

Published: 2025-10-13 | Last Modified: 2026-07-30 | Status: Modified

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.

CVSS Metrics

Base Score: 3.3 (LOW)

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactLOW

Source: [email protected]

Type: Primary

Exploitability Score: 1.8

Impact Score: 1.4

Weaknesses

Source Type Description
[email protected] Primary
en NVD-CWE-noinfo

Affected Products

Vendor Product Version Update Type
linux linux_kernel * <built-in method update of dict object at 0x7d23a59ff980> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d2424609040> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d24246c3b80> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d23a59fe540> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d23a59fda00> Operating System
linux linux_kernel * <built-in method update of dict object at 0x7d23a59ff680> Operating System
linux linux_kernel 6.17 <built-in method update of dict object at 0x7d23bea89680> Operating System
linux linux_kernel 6.17 <built-in method update of dict object at 0x7d2424609bc0> Operating System
linux linux_kernel 6.17 <built-in method update of dict object at 0x7d23a59ffb40> Operating System
linux linux_kernel 6.17 <built-in method update of dict object at 0x7d23a59fd980> Operating System
linux linux_kernel 6.17 <built-in method update of dict object at 0x7d23a59fecc0> Operating System
linux linux_kernel 6.17 <built-in method update of dict object at 0x7d24246c1b00> Operating System

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.17:rc1:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.17:rc2:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.17:rc3:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.17:rc4:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.17:rc5:*:*:*:*:*:*
Yes cpe:2.3:o:linux:linux_kernel:6.17:rc6:*:*:*:*:*:*

References

Notification
Message here