CVE-2025-39964

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/10/2025
Last modified:
14/10/2025

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg<br /> <br /> Issuing two writes to the same af_alg socket is bogus as the<br /> data will be interleaved in an unpredictable fashion. Furthermore,<br /> concurrent writes may create inconsistencies in the internal<br /> socket state.<br /> <br /> Disallow this by adding a new ctx-&gt;write field that indiciates<br /> exclusive ownership for writing.

Impact