Vulnerability report

Exploited in the wild Confirmed confidence In CISA KEV

CVE-2025-39964

crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg

Linux / Linux · affected before *

Severity
CVSS 7.8 · High
Confidence
Confirmed
Exploit status
Exploited in the wild
EPSS
0.8%
First observed
Last observed

Decision summary

What security teams need to know first

Direct answers before the deeper technical record.

What it is

CVE-2025-39964 is crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg affecting Linux Linux. In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes...

Is it exploited?

Yes. Previdian tracks this CVE as a known exploited vulnerability. Confidence is confirmed. Listed in CISA KEV. Also confirmed by third-party sources.

Who is affected?

Linux / Linux affected before *.

What should we do?

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Overview

crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg

In the Linux kernel, the following vulnerability has been resolved:

crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg

Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state.

Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.

Siemens Affected
SIMATIC S7-1500 CPU 1518-4 PN/DP MFP
Before *
Siemens Affected
SIMATIC S7-1500 CPU 1518F-4 PN/DP MFP
Before *
Siemens Affected
SIPLUS S7-1500 CPU 1518-4 PN/DP MFP
Before *
Linux Affected
Linux
Before 0f28c4adbc4a97437874c9b669fd7958a8c6d6ce Before e4c1ec11132ec466f7362a95f36a506ce4dc08c9 Before 1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8 Before 7c4491b5644e3a3708f3dbd7591be0a570135b84 Before 9aee87da5572b3a14075f501752e209801160d3d Before 45bcf60fe49b37daab1acee57b27211ad1574042 Before 1b34cbbf4f011a121ef7b2d7d6e6920a036d5285 2.6.38
Linux Unaffected
Linux
Before 2.6.38 Through 5.10.* Through 5.15.* Through 6.1.* Through 6.6.* Through 6.12.* Through 6.16.* Through *
Published
13 Oct 2025
Exploitation Reported
18 Sep 2026
Attack vector
Local
Complexity
Low
Privileges
Low
User interaction
None

Tags

linux cisa

CVE References

Exploitation evidence

Why Previdian marks this CVE as exploited

Third-party attestation and first-party sensor observation are shown separately so teams can judge the evidence chain.

Exploited in the wild

CISA

Recorded 18 Sep 2026

A trusted third party reported exploitation.

Known exploited vulnerability sources

Per-source evidence links for KEV attestations are available through the Previdian Pro API.

Learn about Pro API access
Source Added
CISA First 2026-09-18 14:30 UTC
CVE 2026-09-18 14:50 UTC
The Hacker News 2026-09-19 00:00 UTC

Detection

Operational artifacts and observed signals

Make the evidence actionable in scanner, SOC, and edge-control workflows.

Observed signals

Request targets
User-Agents
Callback hosts
0
0
0

Request targets and User-Agents available in Pro. Callback host details available in Enterprise.

Scanner coverage

No scanner integrations recorded yet.

Virtual patch status

No Previdian virtual patch is currently available. Future rules ship for ModSecurity, Cloudflare, and AWS WAF.

Learn about virtual patches →

No detection artifacts or sensor request patterns are available for this CVE yet.

Check back as sensor telemetry and scanner integrations are updated.

Risk and context

Severity, weaknesses, and research context

CVSS v3.1

7.8 High
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.8%

Recent mention · Security Affairs

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited...

Read full advisory

All Mentions

Recent mention · Security Affairs

U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog

Security Affairs · 20 Sep 2026

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Below are detailed descriptions of the flaws: At the time of this writing, there are currently no details on how the […]

Recent mention · The Hacker News

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

The Hacker News · 19 Sep 2026

Ravie LakshmananSep 19, 2026Vulnerability / Linux The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2025-39682 (CVSS score: 9.8) - An improper check for unusual or exceptional conditions vulnerability in the TLS receive path that could allow local authenticated users to trigger memory disclosure or denial-of-service (DoS). CVE-2026-53266 (CVSS score: 8.8) - An out-of-bounds...

Timeline

From disclosure to observed exploitation

  1. 00:00 UTC

    KEV confirmed by The Hacker News

    Exploitation attested by an external source

  2. 14:50 UTC

    KEV confirmed by CVE

    Exploitation attested by an external source

  3. 14:30 UTC

    Added to CISA KEV

    Listed in the CISA Known Exploited Vulnerabilities catalog

  4. 13:48 UTC

    CVE published

    Vulnerability disclosed publicly

  5. 07:20 UTC

    CVE ID reserved

    Identifier reserved by the CNA

Pro API

Automate this intelligence

Confidence, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.

  • Evidence confidence and provenance
  • First-party sensor telemetry
  • PoC and scanner references
  • Affected versions and enrichment
  • Automation-ready JSON delivery

GET /api/v2/pro/kevs/CVE-2025-39964

Free JSON includes basic KEV fields
{
  "cve_id": "CVE-2025-39964",
  "confidence": "Confirmed",
  "cvss_score": 7.8,
  "cvss_estimated": false,
  "epss_score": 0.0079,
  "exploit_status": {
    "exploited_in_the_wild": true,
    "active_exploitation_observed": false
  },
  "sensor_telemetry": { "attempts": 0, "sensors": 0 }
}