Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-39964— crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg

EPSS 0.03% · P9

Affected Version Matrix 16

VendorProductVersion RangeStatus
LinuxLinux8ff590903d5fc7f5a0a988c38267a3d08e6393a2< 0f28c4adbc4a97437874c9b669fd7958a8c6d6ceaffected
8ff590903d5fc7f5a0a988c38267a3d08e6393a2< e4c1ec11132ec466f7362a95f36a506ce4dc08c9affected
8ff590903d5fc7f5a0a988c38267a3d08e6393a2< 1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8affected
8ff590903d5fc7f5a0a988c38267a3d08e6393a2< 7c4491b5644e3a3708f3dbd7591be0a570135b84affected
8ff590903d5fc7f5a0a988c38267a3d08e6393a2< 9aee87da5572b3a14075f501752e209801160d3daffected
8ff590903d5fc7f5a0a988c38267a3d08e6393a2< 45bcf60fe49b37daab1acee57b27211ad1574042affected
8ff590903d5fc7f5a0a988c38267a3d08e6393a2< 1b34cbbf4f011a121ef7b2d7d6e6920a036d5285affected
2.6.38affected
… +8 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-39964

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
Source: NVD (National Vulnerability Database)
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于af_alg_sendmsg允许并发写入,可能导致内部套接字状态不一致。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 ~ 0f28c4adbc4a97437874c9b669fd7958a8c6d6ce -
LinuxLinux 2.6.38 -

II. Public POCs for CVE-2025-39964

#POC DescriptionSource LinkShenlong Link
1CVE-2025-39964 EXPhttps://github.com/n1k0oowang/CVE-2025-39964_EXPPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-39964

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2025-39964

No comments yet


Leave a comment