Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-19 · updated: 2026-09-19 · tags: [cve] · confidence: medium · severity: high · affected_sectors: [global] · au_impact: false

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.

CISA added CVE-2025-39964 (Linux kernel race condition) and CVE-2026-53266 (Linux kernel out-of-bounds write) to its Known Exploited Vulnerabilities catalog on 18 September, both on evidence of active exploitation, alongside the earlier additions this week of CVE-2026-58704 (Google Pixel), CVE-2026-76460 (Cisco Identity Services Engine) and CVE-2026-87886 (Acronis Backup).

Attribute Detail
CVE CVE-2025-39964
CVSS 7.8 (high)
Vendor / product Linux — Linux Kernel (crypto / af_alg AF_ALG socket subsystem)
Reported 2026-09-19