CVE-2025-39964 – Critical Linux Kernel Race Condition in AF_ALG Crypto Socket (CISA KEV, Active Exploitation)

CVE-2025-39964 is a Linux Kernel vulnerability classified as a race condition in the AF_ALG crypto socket interface. Rated CVSS 7.8 (High) by the vendor and CVSS 5.5 (Medium) by NVD, it allows local unprivileged users to trigger memory corruption, potentially leading to privilege escalation or denial of service. The flaw has been added to the CISA KEV catalog and is currently under active exploitation in the wild.

TL;DR – Key Takeaways

  • Severity: Critical / High — CVSS 7.8 (CNA), Medium CVSS 5.5 (NVD)
  • Impact: Privilege escalation, arbitrary kernel writes, potential Docker/container escape
  • Affected: Linux Kernel versions including 6.17 (rc1–rc6); also impacts select Siemens Simatic S7-1500 firmware
  • Exploitation: Confirmed active exploitation; listed in CISA KEV
  • Action: Patch immediately or disable unprivileged user namespaces

Overview

CVE-2025-39964 stems from a concurrency flaw in the AF_ALG cryptographic API within the Linux Kernel. Specifically, issuing two concurrent write operations to the same AF_ALG socket leads to unpredictable data interleaving and internal socket state corruption. This can result in out-of-bounds memory access, enabling an attacker to escalate privileges from an unprivileged user to root.

This vulnerability was publicly disclosed and added to the CISA Known Exploited Vulnerabilities (KEV) catalog on September 18, 2026, following reports of real-world exploitation.


Technical Details

The root cause lies in the lack of synchronization around the af_alg_sendmsg() function. When two threads simultaneously issue sendmsg() calls to the same AF_ALG socket, the kernel fails to serialize these operations properly. The fix introduces a new ctx->write field to enforce exclusive ownership during write operations.

According to public disclosures:

  • Concurrent writes cause data interleaving in the scatter-gather list (sg) used internally.
  • A wait path drops a lock while a merge path proceeds, leaving inconsistent state.
  • Subsequent appends read sg[-1], resulting in a controlled dereference and arbitrary kernel write.
  • This can be chained with core_pattern pipe handling to gain root access — including from inside containers.

The bug has existed in the kernel tree since at least 2011, making it a long-standing and high-risk issue.

For key indicators, exploit activity over time, and detailed signal data, see the CVE page.


Severity & Impact

MetricValue
CVE IDCVE-2025-39964
VendorLinux
ProductLinux Kernel
CWECWE-362 – Race Condition
CVSS (CNA)7.8 High
CVSS (NVD)5.5 Medium
Exploitation StatusActive Exploitation
CISA KEVYes

Impact:

  • Local privilege escalation to root
  • Arbitrary kernel memory writes
  • Denial of service via kernel crash
  • Potential container escape (e.g., Docker)

Affected Products

  • Linux Kernel versions up to and including 6.17 (rc1 through rc6)
  • Select Siemens Simatic S7-1500 CPU 1518 modules and firmware (non-kernel context)

For the full list of affected products and versions, see CVE page.


Actionable Insights

  • Active exploitation confirmed: Multiple sources report ongoing attacks leveraging this flaw shortly after its addition to CISA KEV.
  • Long-standing exposure: The vulnerability has been present in the kernel since 2011, meaning many legacy systems remain vulnerable.
  • Container risk: The exploit chain includes a path to Docker host escape, increasing urgency for cloud-native environments.
  • Detection signals: Look for anomalous sendmsg() behavior on AF_ALG sockets, unexpected root shell spawns from low-privilege users, or kernel panics related to crypto subsystem crashes.

Remediation & Mitigation

  1. Patch the kernel immediately using updates from your distribution vendor (e.g., RHEL, Ubuntu, Debian, SUSE).
  2. Reboot systems post-patch to ensure the updated kernel is loaded.
  3. As a temporary mitigation, disable unprivileged user namespaces:
    sysctl -w kernel.unprivileged_userns_clone=0
    # Or
    sysctl -w user.max_user_namespaces=0
    
  4. Monitor system logs (dmesg, auditd) for signs of exploitation:
    • Unusual sendmsg() calls on AF_ALG sockets
    • Kernel NULL pointer dereferences or panics in crypto paths
    • Unexpected setuid(0) calls from non-root processes
  5. Enforce strict SELinux/AppArmor policies to limit access to sensitive kernel interfaces.

References


Summary

CVE-2025-39964 represents a serious and actively exploited flaw in the Linux Kernel’s AF_ALG crypto subsystem. With a CVSS score of 7.8 and confirmed use in the wild, defenders must treat this as urgent. Organizations running affected kernels — particularly those hosting containers or untrusted users — should patch immediately and monitor for signs of compromise.

#CVE202539964 #Linux #KernelSecurity #CISAKEV #PrivilegeEscalation #ActiveExploitation #AFALG