In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.
CISA added CVE-2025-39964 (Linux kernel race condition) and CVE-2026-53266 (Linux kernel out-of-bounds write) to its Known Exploited Vulnerabilities catalog on 18 September, both on evidence of active exploitation, alongside the earlier additions this week of CVE-2026-58704 (Google Pixel), CVE-2026-76460 (Cisco Identity Services Engine) and CVE-2026-87886 (Acronis Backup).
| Attribute | Detail |
|---|---|
| CVE | CVE-2025-39964 |
| CVSS | 7.8 (high) |
| Vendor / product | Linux — Linux Kernel (crypto / af_alg AF_ALG socket subsystem) |
| Reported | 2026-09-19 |