๐ฅ This vulnerability is being actively exploited in the wild (CISA Known Exploited Vulnerabilities catalog)
CVE-2025-39964: Linux Kernel Race Condition Vulnerability
Summary
The Linux Kernel has a race condition vulnerability (a bug where concurrent, simultaneous operations interfere with each other) in AF_ALG sockets (a Linux interface for cryptographic operations) that causes data to be mixed up unpredictably when multiple writes happen at the same time, corrupting the socket's internal state. This vulnerability is currently being actively exploited by attackers. The source text does not provide specific technical steps to fix the issue, only that organizations must follow vendor instructions and comply with CISA's BOD 26-04 guidance on security patching, with a deadline of September 21, 2026.
Vulnerability Details
EPSS: 0.3%
Yes
๐ฅ Actively Exploited
September 17, 2026
Classification
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-39964
First tracked: September 18, 2026 at 02:00 PM
Classified by LLM (prompt v3) ยท confidence: 95%