Linux Kernel AF_ALG Race Condition Vulnerability

Release Date: 18th September 2026 (Added 21 September 2026)

Impact : HIGH

TLP Rating: Clear

The Department of Communications and Digital Transformation (DCDT) through CERT Vanuatu (CERTVU), provides the following advisory.

This alert is relevant to Organizations and System/Network administrators that utilize the above product(s). This alert is intended to be understood by technical users and systems administrators.

What is it?

CVE-2025-39964 is a high-severity race condition vulnerability in the Linux kernel's cryptographic user API (AF_ALG). The flaw allows two concurrent writes to the same AF_ALG socket, which can interleave request data unpredictably and leave the socket's internal state inconsistent.

Reference

  1. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
  2. https://www.cve.org/CVERecord?id=CVE-2025-39964
  3. https://nvd.nist.gov/vuln/detail/CVE-2025-39964