Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2025-39964
CVE
CVE-2025-39964
View on NVD ↗
crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg
Source Articles
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation in the wild. The vulnerabilities—CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964—allow local attackers to achieve memory disclosure, denial-of-service, or local privilege escalation. Red Hat has acknowledged active exploitation and labeled the flaws as high risk, urging immediate remediation. Federal agencies are required to patch these vulnerabilities by September 21, 2026, per Binding Operational Directive 26-04.
hacker-news
Sep 19, 2026