Skip to content

Data collected

CVEs Live

CVE-2025-39964: Linux Kernel Race Condition Vulnerability

Linux · Kernel

Listed by CISA as exploited in the wild since 18 Sep 2026. Below: exploitation status, EPSS and every published CVSS, each with its source, then affected versions and references.

Build snapshot collected · KEV catalog 2026.10.02 · EPSS of 2 Oct 2026 · not a live feed: collected once, at build time

Description

as written by CISA (KEV catalog)

Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state.

Required action

CISA KEV

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Affected products and versions

CVE record · Linux

  • Linux · Linux

    • affected: from 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 before 0f28c4adbc4a97437874c9b669fd7958a8c6d6ce
    • affected: from 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 before e4c1ec11132ec466f7362a95f36a506ce4dc08c9
    • affected: from 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 before 1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8
    • affected: from 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 before 7c4491b5644e3a3708f3dbd7591be0a570135b84
    • affected: from 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 before 9aee87da5572b3a14075f501752e209801160d3d
    • affected: from 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 before 45bcf60fe49b37daab1acee57b27211ad1574042
    • affected: from 8ff590903d5fc7f5a0a988c38267a3d08e6393a2 before 1b34cbbf4f011a121ef7b2d7d6e6920a036d5285
  • Linux · Linux

    • affected: 2.6.38
    • unaffected: before 2.6.38
    • unaffected: from 5.10.245 through 5.10.*
    • unaffected: from 5.15.194 through 5.15.*
    • unaffected: from 6.1.154 through 6.1.*
    • unaffected: from 6.6.108 through 6.6.*
    • unaffected: from 6.12.49 through 6.12.*
    • unaffected: from 6.16.9 through 6.16.*
    • unaffected: from 6.17 through *

Status words (affected, unaffected, unknown) and version bounds are copied from the record. An upper bound such as “before 7.1.0” usually marks the first fixed version; confirm in the vendor advisory before planning an upgrade.

References

CISA KEV notes and CVE record

EPSS over the last 30 days

See also: all Linux entries in KEV · the full KEV catalog

Questions about CVE-2025-39964

Is CVE-2025-39964 being exploited?

Yes, according to CISA. CVE-2025-39964 was added to the Known Exploited Vulnerabilities catalog on 18 Sep 2026, which CISA does only with reliable evidence of exploitation in the wild. The catalog field for ransomware campaign use says "Unknown".

What is the deadline to remediate CVE-2025-39964?

CISA set 21 Sep 2026 as the due date for US Federal Civilian Executive Branch agencies. The date is binding only for those agencies; other organisations can read it as a measure of urgency.

What is the EPSS score of CVE-2025-39964?

1.00%, in the 61th percentile, in the FIRST EPSS model of 2 Oct 2026. It estimates the probability of exploitation activity in the following 30 days. For a CVE already in KEV the score is secondary: exploitation has been observed.

How severe is CVE-2025-39964?

NVD rates it 5.5 MEDIUM (CVSS 3.1); 416baaa9-dc9f-4396-8d5f-8c081fb06d67 rates it 7.8 HIGH (CVSS 3.1). These are the published assessments as of 3 Oct 2026; this site does not rescore.

Which product does CVE-2025-39964 affect?

Linux Kernel, as named in the CISA catalog. The affected versions listed in the CVE record are on this page; the vendor advisory in the references is the authority on fixed versions.

Related sections