Cyber Resilience
← All news

KEV: CVE-2025-39964 — Linux Kernel (Linux Kernel Race Condition Vulnerability)

Our takeCISA added CVE-2025-39964 to the KEV catalog: a Linux kernel race condition on AF_ALG sockets that is already under active exploitation. Patch it if you run affected kernels; most smaller teams on managed cloud Linux can ignore this one while enterprises with self-hosted workloads should treat it as emergency.
Sources (4)
What this means for you — Security leader:CISA added CVE-2025-39964 (Linux kernel race condition in AF_ALG sockets) to the KEV catalog; it is actively exploited in the wild. Patch per your distro guidance on the emergency cycle and ensure all Linux systems are covered by your kernel update process.
What this means for you — Lean IT orgs:If you run your own Linux servers, this kernel flaw is being exploited in the wild — check with your hosting provider or whoever manages the servers and make sure they apply the available updates promptly.
What this means for you — MSP:CISA added CVE-2025-39964 (Linux kernel AF_ALG race condition) to KEV; it is under active exploitation. Review all client Linux estates (on-prem, VMs, cloud instances) and confirm the relevant kernel patches or mitigations are deployed.
What this means for you — Researcher:CISA added CVE-2025-39964 to the KEV catalog citing active exploitation. Linux kernel race condition in concurrent AF_ALG socket writes; check your distro for the fix and note that exploitation is now confirmed.