Linux Kernel AF_ALG Race Condition Vulnerability
Release Date: 18th September 2026 (Added 21 September 2026)
Impact : HIGH
TLP Rating: Clear 
The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.
This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.
What is it?
CVE-2025-39964 is a high-severity race condition vulnerability in the Linux kernel's cryptographic user API (AF_ALG). The flaw allows two concurrent writes to the same AF_ALG socket, which can interleave request data unpredictably and leave the socket's internal state inconsistent.
What are the systems affected?
The following Linux kernel versions are affected:
- Linux kernel versions before 5.10.245
- Linux kernel versions before 5.15.194
- Linux kernel versions before 6.1.154
- Linux kernel versions before 6.6.108
- Linux kernel versions before 6.12.49
- Linux kernel versions before 6.16.9
This affects mainstream Linux distributions (including Debian, Ubuntu, Red Hat, SUSE, Oracle Linux, and Amazon Linux) running a kernel predating these fixed releases.
Not affected / patched version:
- Linux kernel 5.10.245, 5.15.194, 6.1.154, 6.6.108, 6.12.49, 6.16.9, or 6.17 and later
- Distribution-specific patched kernel packages released by your Linux vendor
What does this mean?
Successful exploitation may allow attackers to:
- Crash the affected system, causing a denial of service
- Corrupt the results of in-flight cryptographic operations, undermining data integrity
- Repeat the attack from a low-privileged, unprivileged local account with no special access required
Mitigation process?
CERTVU recommends the following:
-
Apply the vendor patch immediately
Upgrade to a kernel release that ships the fix (5.10.245, 5.15.194, 6.1.154, 6.6.108, 6.12.49, 6.16.9, or 6.17+), or install your distribution's latest kernel security update. -
Reboot into the patched kernel
-
Treat this as high priority
Reference
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cve.org/CVERecord?id=CVE-2025-39964
- https://nvd.nist.gov/vuln/detail/CVE-2025-39964
- Download advisory (English): Linux Kernel AF_ALG Race Condition Vulnerability