← Back

CVE-2025-39964

nvd nist
Published: Oct 13, 2025Modified: Sep 19, 2026CISA KEV

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.

Affected (14)

1 product
Linux Kernel
2 products
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 2.6.38 to 5.10.245
From 5.11 to 5.15.194
From 5.16 to 6.1.154
From 6.13 to 6.16.9
From 6.2 to 6.6.108
From 6.7 to 6.12.49
Version 6.17 rc1
Version 6.17 rc2
Version 6.17 rc3
Version 6.17 rc4
Version 6.17 rc5
Version 6.17 rc6
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 3.1.6
Running on/withPlatform Versions
Siemens
Simatic S7 1500 Cpu 1518 4 Pn/dp Mfp
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 3.1.6
Running on/withPlatform Versions
Siemens
Simatic S7 1500 Cpu 1518f 4 Pn/dp Mfp
All versions

References (9)

Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
Patch
Source: 0b142b55-0307-4c5a-b3c9-f314f3fb7c5e
Third Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.