EUVD Vulnerability Catalog
Actively Exploited (KEV)
EUVD-2025-34068
Severity: HIGH
Base Score: 7.8
CVSS Version: 3.1
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved:
crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
Issuing two writes to the same af_alg socket is bogus as the
data will be interleaved in an unpredictable fashion. Furthermore,
concurrent writes may create inconsistencies in the internal
socket state.
Disallow this by adding a new ctx->write field that indiciates
exclusive ownership for writing.
CVSS Vector Analysis
Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
▪
Attack Vector (AV): Local
▪
Attack Complexity (AC): Low
▪
Privileges Required (PR): Low
▪
User Interaction (UI): None
▪
Scope (S): Unchanged
▪
Confidentiality Impact (C): High
▪
Integrity Impact (I): High
▪
Availability Impact (A): High
Affected Vendors & Systems
Vendor
Linux
References & Advisory Links
- https://git.kernel.org/stable/c/0f28c4adbc4a97437874c9b669fd7958a8c6d6ce
- https://git.kernel.org/stable/c/e4c1ec11132ec466f7362a95f36a506ce4dc08c9
- https://git.kernel.org/stable/c/1f323a48e9b5ebfe6dc7d130fdf5c3c0e92a07c8
- https://git.kernel.org/stable/c/7c4491b5644e3a3708f3dbd7591be0a570135b84
- https://git.kernel.org/stable/c/9aee87da5572b3a14075f501752e209801160d3d
- https://git.kernel.org/stable/c/45bcf60fe49b37daab1acee57b27211ad1574042
- https://git.kernel.org/stable/c/1b34cbbf4f011a121ef7b2d7d6e6920a036d5285
Metadata Profile
Database Authority
European Union Agency for Cybersecurity (ENISA) EUVD
Assigner
Linux
EPSS Probability
0.32
Known Aliases
GHSA-wr5g-mfhw-rpfj
CVE-2025-39964
Published On
2025-10-13
Last Updated
2026-09-18
Exploited Since
2026-09-18