CVE-2025-39964(linux / linux_kernel)

LOWCVSS 5.5 · MEDIUMCISA KEV

Signal is active with 9 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.

1.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-09-21. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-362

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • linux_kernel
  • simatic_s7-1500_cpu_1518-4_pn\/dp_mfp
  • simatic_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware
  • simatic_s7-1500_cpu_1518f-4_pn\/dp_mfp

Threat summary

  • 21 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 12 mentions (2026-09-18); latest day: 9
  • 21 total mentions across 2 days

Affected systems

Products
linux_kernelsimatic_s7-1500_cpu_1518-4_pn\/dp_mfpsimatic_s7-1500_cpu_1518-4_pn\/dp_mfp_firmwaresimatic_s7-1500_cpu_1518f-4_pn\/dp_mfpsimatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmware

1 version affected across 5 products

Deep dive

Activity timeline21 mentions / 2d
036912Mentions · 2026-09-18: 12Mentions · 2026-09-19: 909-1809-19
Referenced assets13 URLs
Full discourse20 posts
  • CISA Cyber@CISACyber

    🛡 We added Linux Kernal race condition vulnerability CVE-2025-39964 & out-of-bounds write vulnerability CVE-2026-53266 to our KEV Catalog. Visit https://go.dhs.gov/Z3Q & apply mitigations to protect your org from cyberattacks. #Cybersecurity #InfoSec https://t.co/SpBCm1GlhM

    1401945.7K
    302.4K followersView on X
  • kokumօtօ@__kokumoto

    米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに2件と1件の脆弱性を追加。全てLinuxカーネルで、CVE-2025-39964、CVE-2026-53266、CVE-2025-39682。対処期限は3日後の9/21。ランサムウェアによる悪用は不知。 https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-two-known-exploited-vulnerabilities-catalog https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-one-known-exploited-vulnerability-catalog

    210471.1K
    7.8K followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🚨 CISA ADDS TWO LINUX KERNEL VULNS TO KEV CATALOG CISA has added two Linux Kernel vulnerabilities to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation (catalog date 2026-09-18). CVEs added: • CVE-2025-39964 — race condition (AF_ALG socket concurrent writes / state inconsistency) • CVE-2026-53266 — out-of-bounds write (ebtables SNAT target writing into nonlinear skb fragment) Due date: 2026-09-21 · Forensic triage required: Yes · Known ransomware use: Unknown ⚠️ Analyst Note: This is an official CISA KEV addition reflecting active exploitation evidence — not an unverified underground claim. Organizations should prioritize patching per BOD 26-04 guidance and vendor/kernel updates. CISA alert: https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-two-known-exploited-vulnerabilities-catalog KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog #DDW #DarkWeb #CISA #KEV #Linux #CyberSecurity

    100524.9K
    203.4K followersView on X
  • Dark Web Intelligence@DailyDarkWeb

    🚨 CISA ADDS LINUX KERNEL TLS CVE-2025-39682 TO KEV CISA has added CVE-2025-39682 (Linux Kernel TLS) to its Known Exploited Vulnerabilities Catalog (2026-09-18; catalog count noted at 1716) based on evidence of active exploitation. Per CISA / technical notes: • Improper check in the Linux Kernel TLS receive path • A zero-length record from rx_list can bypass intended recvmsg() record-type handling • Due date: 2026-09-21 · Forensic triage required: Yes ⚠️ Analyst Note: This is a THIRD same-day Linux Kernel KEV addition — distinct from today’s earlier pair (CVE-2025-39964 + CVE-2026-53266). Official CISA active-exploitation listing: patch ASAP and follow BOD 26-04 forensic-triage guidance where applicable. CISA alert: https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-one-known-exploited-vulnerability-catalog KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog Kernel fix example: https://git.kernel.org/stable/c/2902c3ebcca52ca845c03182000e8d71d3a5196f NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-39682 #DDW #DarkWeb #CVE #Linux #KEV #ThreatIntelligence #CyberSecurity

    000314.5K
    203.4K followersView on X
  • SOCMinute@SOCMinute

    CISA adds two actively exploited Linux Kernel vulnerabilities (CVE-2025-39964 & CVE-2026-53266) to the KEV Catalog. Federal agencies must prioritize patching these threats under BOD 26-04. Stay ahead with SOC Minute updates. #CISA #LinuxKernel #PatchManagement https://t.co/PfSKBnqzG6

    1001028
    13 followersView on X
  • VulnTracker@vuln_tracker

    Three Linux kernel vulnerabilities. All confirmed exploited by CISA on the same day. CVE-2025-39682 (CVSS 9.8): a remotely triggerable flaw in the TLS receive path. CVE-2026-53266 (8.8): an out-of-bounds write in netfilter's ebtables ARP rewrite. CVE-2025-39964 (7.8): a race condition in AF_ALG sockets that corrupts crypto operations. Federal deadline: September 21. If you run Linux, patch now. Details: http://vulntracker.io #Linux #CVE #CISA #VulnTracker

    00010114
    754 followersView on X
  • sunil kumawat@Sunil_kumawat17

    Who is hit: • CVE-2026-53266: unprivileged memory corruption when ebtables SNAT rewrites ARP into splice-backed page. Not default, but real on gateways. • CVE-2025-39964: AF_ALG concurrent writers → crypto corruption/DoS. • CVE-2025-39682: TLS mishandles zero-length rx_list.

    1000047
    19 followersView on X
  • sunil kumawat@Sunil_kumawat17

    CISA put 3 Linux kernel flaws on KEV yesterday—actively exploited. Federal due: Sep 21. CVE-2025-39682 (TLS zero-length rx_list), CVE-2026-53266 (ebtables SNAT ARP → OOB write), CVE-2025-39964 (AF_ALG race). Linux self-hosters/cloud VMs: update weekend, not “wait for LTS”

    1000055
    19 followersView on X
  • Christopher Elliott@Chris_L_Elliott

    CISA put two Linux kernel bugs on KEV today: CVE-2025-39964 (af_alg concurrent-write race) and CVE-2026-53266 (ebt_snat ARP rewrite on bridge netfilter). Already exploited — not a theoretical advisory pile. If your fleet still treats kernel updates like quarterly hygiene, these are the ones that make that schedule look silly. AF_ALG and bridge netfilter show up on more "boring" prod boxes than people want to admit. https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-two-known-exploited-vulnerabilities-catalog

    1000037
    49 followersView on X
  • NotCVE@notCVE

    ⚠️ ACTIVELY EXPLOITED — added to CISA KEV 2026-09-18 CVE-2025-39964: Linux Kernel Race Condition Vulnerability CVSS 7.8 · EPSS 0.3% · 2 public exploits Details, versions & intel → https://notcve.org/cve/CVE-2025-39964 https://t.co/ASAweorZv1

    1000045
    70 followersView on X
  • PCMedicalist@PCMedicalist

    🔐 Daily Security & Standards Brief (Sep 19) CVE-2025-39964--Linux Kernel Race Condition: patch Linux Kernel Race Condition and verify the fix held. Full digest 👇 via PCMedicalist #CyberSecurity #InfoSec https://t.co/fXMHM73Gii

    000002
    157 followersView on X
  • Samit Hota @HotaSamit

    Linux Kernel Race Condition (CVE-2025-39964): AF_ALG Socket Analysis CVE-2025-39964 is a high-severity race condition in the Linux Kernel's AF_ALG socket subsystem that allows local unprivileged memory… Full write-up → link in bio #cybersecurity #infosec #cve #kev #linux https://t.co/8zQG0ibBQD

    000007
    23 followersView on X
  • LinuxGeek 🐧@NewsOfLinux

    @TheHackersNews CVE-2025-39964 is an AF_ALG socket race, CVE-2026-53266 an out-of-bounds write in the ebtables SNAT target, CVE-2025-39682 a zero-length record in the kernel TLS receive path. Added to KEV on the 18th, all three due the 21st. That is a three-day fuse.

    0000052
    125 followersView on X
  • The Daily Tech Feed@dailytechonx

    Three severe Linux kernel vulnerabilities—CVE-2025-39682, CVE-2026-53266 & CVE-2025-39964—are now confirmed exploited in the wild. Red Hat’s advisories are live. US agencies face a patch deadline of September 21 under CISA’s KEV and BOD-26-04 mandates. Threats span privilege escalation, memory disclosure & DoS. Summary: audit local access, apply kernel updates fast. #SecurityNews #Linux #CVE #CISA #KernelVulnerabilities #PrivEsc #SecurityNews #Linux #Kernel #CVE #CISA #PrivEsc #Vulnerabilities https://thedailytechfeed.com/cisa-adds-three-critical-linux-kernel-bugs-to-exploited-list/

    0000042
    725 followersView on X
  • ITフレブル【実務派エンジニア速報】@eng_digest_jp

    【Linux更新、期限は9月21日】 ・CVE-2025-39964をKEV追加 ・Linux Kernelの競合状態 ・対応期限は2026年9月21日 既知悪用として期限付き対応です。 #CISA https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2025-39964

    0000022
    5 followersView on X
  • Venkata Satish Guttula 🛰️@snakeyesV1

    News: CISA put Linux kernel CVE-2025-39964 (AF_ALG race) and CVE-2026-53266 (ebtables SNAT write) on KEV Sep 18. Hits unpatched Linux hosts; both under active use. Apply your distro kernel update now; if stuck, blacklist af_alg and drop ebtables ARP rewrite. https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-two-known-exploited-vulnerabilities-catalog

    0000064
    3.0K followersView on X
  • Anthony Bahn@HoustonIntrove1

    Linux kernel CISA KEV (today): CVE-2025-39964 and CVE-2026-53266. AF_ALG race condition and out-of-bounds write. CISA cites active exploitation evidence. Patch or roll vendor kernel updates across managed Linux fleets now. #CVE #KEV

    0000029
    23 followersView on X
  • Security Arsenal, LLC@SecurityAr58409

    🔒 #CyberSecurity CISA KEV Alert: CVE-2025-39964 and CVE-2026-53266 Linux Kernel Exploits — Detec… "On September 18, 2026, CISA added two Linux kernel vulnerabilities to its Known Exploited…" 🔗 https://securityarsenal.com/blog/cisa-kev-alert-cve-2025-39964-and-cve-2026-53266-linux-kernel-exploits-detection-and-remediation-guide #CyberSecurity #ThreatIntel #critical #zeroday #cve

    0000035
    31 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc

    TRC analysis shows attackers exploiting Linux kernel vulnerabilities CVE-2025-39964 and CVE-2026-53266 to gain root privileges and move laterally across network segments. Runtime segmentation helps contain post-compromise activity when kernel-level access is achieved. #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/cisa-kev-linux-kernel-cve-2025-39964-cve-2026-53266-september-2026

    0000050
    2.0K followersView on X
  • Security Arsenal, LLC@SecurityAr58409

    🔒 #CyberSecurity CVE-2025-39964: Linux Kernel AF_ALG Race Condition Added to CISA KEV — Detectio… "On September 18, 2026, CISA added CVE-2025-39964 to its Known Exploited…" 🔗 https://securityarsenal.com/blog/cve-2025-39964-linux-kernel-afalg-race-condition-added-to-cisa-kev-detection-and-remediation-guide #CyberSecurity #ThreatIntel #cve202539964 #critical #cisakev

    0000034
    31 followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
OSlinuxlinux_kernel---
OSlinuxlinux_kernel6.17--
OSlinuxlinux_kernel6.17--
OSlinuxlinux_kernel6.17--
OSlinuxlinux_kernel6.17--
OSlinuxlinux_kernel6.17--
OSlinuxlinux_kernel6.17--
HWsiemenssimatic_s7-1500_cpu_1518-4_pn\/dp_mfp---
OSsiemenssimatic_s7-1500_cpu_1518-4_pn\/dp_mfp_firmware---
HWsiemenssimatic_s7-1500_cpu_1518f-4_pn\/dp_mfp---
OSsiemenssimatic_s7-1500_cpu_1518f-4_pn\/dp_mfp_firmware---

Explore more