CISA has added CVE-2025-39964, the Linux Kernel Race Condition Vulnerability, to its Known Exploited Vulnerabilities (KEV) catalogue. The flaw affects the Linux Kernel and allows concurrent writes to the same AF_ALG socket to interleave unpredictably, creating inconsistencies in the socket’s internal state.
The vulnerability is a race condition in the kernel’s AF_ALG socket handling. An attacker able to trigger concurrent writes could cause data corruption or inconsistent socket state. The NVD assigns it a CVSS score of 7.8 (High). The patch status is unknown, although stable-kernel fixes are referenced in the KEV entry.
KEV inclusion confirms that attackers are actively exploiting the vulnerability. The entry does not identify use in ransomware campaigns. CISA set 21 September 2026 as the remediation deadline for affected federal agencies.
CISA requires organisations to apply mitigations in accordance with vendor instructions, comply with BOD 26-04 guidance and the Forensics Triage Requirements, follow applicable BOD 26-04 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. FCEB agencies are directly affected by this requirement; all organisations should review their Linux Kernel exposure, including affected products that incorporate the open-source component.
See the NVD entry and CISA KEV catalogue for full details.