CVE-2025-39964 actively exploited: Linux Kernel Race Condition Vulnerability
CISA added CVE-2025-39964, a race condition in Linux Kernel, to its Known Exploited Vulnerabilities catalogue. It allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. Federal agencies must remediate by September 21, 2026.