CVE-2025-39964

KEV
🔴 Łataj teraz

Błąd w jądrze Linuxa pozwalał na nieprzewidywalne przeplatanie danych przy równoczesnych zapisach w gnieździe af_alg.

CVSS
7.8
EPSS
0.3%
Exploit
weaponized
Vendor
linux
Opis źródłowy (NVD)

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.8
CISA KEV (aktywnie wykorzystywane)Tak
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2025-10-13 14:15:34 UTC
Ostatnia modyfikacja (NVD)2026-09-18 13:17:09 UTC
Referencje