← All CVEs

CVE-2025-39964

high · 7.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Added 2026-09-18Remediation due 2026-09-21

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.

7.8
CVSS
0.3%
EPSS (exploit prob.)
26th
EPSS percentile
2025-10-13
Published

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-362

Affected products

VendorProductAffected versions
linuxlinux_kernel>= 2.6.38, < 5.10.245
linuxlinux_kernel>= 5.11, < 5.15.194
linuxlinux_kernel>= 5.16, < 6.1.154
linuxlinux_kernel>= 6.2, < 6.6.108
linuxlinux_kernel>= 6.7, < 6.12.49
linuxlinux_kernel>= 6.13, < 6.16.9
linuxlinux_kernel6.17
linuxlinux_kernel6.17
linuxlinux_kernel6.17
linuxlinux_kernel6.17
linuxlinux_kernel6.17
linuxlinux_kernel6.17
siemenssimatic_s7-1500_cpu_1518-4_pn/dp_mfp_firmware>= 3.1.6
siemenssimatic_s7-1500_cpu_1518-4_pn/dp_mfpall versions
siemenssimatic_s7-1500_cpu_1518f-4_pn/dp_mfp_firmware>= 3.1.6
siemenssimatic_s7-1500_cpu_1518f-4_pn/dp_mfpall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2025-39964