CVE coverage
View on NVD →
CVE-2025-39964
CVSS 7.8
Actively exploited (KEV)
no coverage
In the Linux kernel, the following vulnerability has been resolved:
crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
Issuing two writes to the same af_alg socket is bogus as the
data will be interleaved in an unpredictable fashion. Furthermore,
concurrent writes may create inconsistencies in the internal
socket state.
Disallow this by adding a new ctx->write field that indiciates
exclusive ownership for writing.
Detection rules
No detection found — yet
None of Sigma, Elastic, Splunk ESCU, YARA, Microsoft Sentinel, Snort, or Suricata currently has a rule referencing CVE-2025-39964.
This CVE is on CISA's Known Exploited Vulnerabilities list. It is being exploited in the wild with no public detection rule — worth writing one.