A Linux kernel vulnerability related to AF_ALG remained patched for approximately a year before being added to the U.S. Cybersecurity and Infrastructure Security Agency (CISA) catalog of actively exploited vulnerabilities. The CVE-2025-39964 case raises an important issue for Linux administrators: the time between a patch becoming available and a formal security alert can be much longer than the response window that follows.

Key facts about CVE-2025-39964 in 20 seconds

  • The flaw affects AF_ALG, the Linux kernel’s cryptographic interface, and is related to concurrent writes to the same socket.
  • Researcher Muhammad Alifa Ramdhan developed an exploit that earned $113,337 from Google’s kernelCTF program.
  • The vulnerability was patched in 2025, while CISA added it to the KEV catalog on September 18, 2026.
  • CISA set September 21 as the remediation deadline for affected systems under its applicable criteria.
  • Another AF_ALG flaw, known as Copy Fail, brought the kernel subsystem back into focus in 2026.

The timing is what makes this case particularly relevant to Linux administration. CVE-2025-39964 did not appear in CISA’s catalog immediately after becoming public. The fix was already available when the U.S. agency added it to its Known Exploited Vulnerabilities (KEV) catalog, which is used to identify vulnerabilities for which there is evidence of active exploitation.

That changes the practical picture depending on the state of the system. A server that had already incorporated a kernel version containing the fix did not need to wait for CISA’s alert to be protected against this specific flaw. On a machine still running a vulnerable version, however, the KEV listing increased the priority of remediation.

A Race Condition in AF_ALG

CVE-2025-39964 affects AF_ALG, a kernel interface that allows userspace programs to use cryptographic operations provided by Linux. The problem was related to the possibility of performing concurrent writes to the same socket.

The description published by the kernel security team states that two simultaneous writes could cause data to be interleaved unpredictably and create inconsistencies in the socket’s internal state. The solution introduced an exclusive ownership mechanism to prevent multiple writers from using that path simultaneously.

Researcher Muhammad Alifa Ramdhan discovered the problem while analyzing kernel code in 2025. According to the account included in the original research, the investigation did not use artificial intelligence. Ramdhan and Bing-Jhong Billy Jheng later developed an exploitation chain capable of obtaining root privileges and escaping certain container environments.

That work ended up in Google’s kernelCTF program, which awarded $113,337 for the exploit. The figure is documented in the IDNSEC research and references to the researchers’ work.

The fix was prepared to prevent concurrent writes to the AF_ALG socket and subsequently reached maintained Linux branches and distributions. Ubuntu, for example, maintains a dedicated entry for CVE-2025-39964 and currently identifies it as a vulnerability included in CISA’s KEV catalog.

There is an important detail regarding the dates. The kernel’s CVE announcement is dated October 13, 2025, while the original research cited by OpenSecurity places the preparation of the fix in September. These are different milestones: the existence of a code change, its integration into maintained branches, and the formal publication of the CVE identifier do not necessarily happen on the same day.

The Patch Arrived Before CISA’s Alert

CISA added CVE-2025-39964 to its KEV catalog on September 18, 2026, and set September 21 as the due date. The vulnerability entry identifies the issue as a kernel race condition and links it to AF_ALG.

The time difference is approximately one year between the fix and the KEV listing. For Linux administrators, this is a reminder that CISA’s catalog does not replace tracking security updates from individual Linux distributions.

There is also a distinction between the moment a flaw is fixed and the moment an organization establishes a specific response requirement. CISA uses KEV as one signal for prioritizing vulnerabilities, but a patch may have been available much earlier.

This issue becomes more relevant with BOD 26-04, a directive published by CISA in June 2026. The directive establishes a prioritization system based on factors such as public exposure of the asset, whether the CVE is listed in KEV, the possibility of automating the attack, and its technical impact. Certain combinations require remediation within three days and may also require a forensic review.

CISA’s documentation also states that measures applied to an asset can affect the applicable deadlines. Temporarily taking a system offline, for example, can change the exposure condition used to determine the required response.

The CVE-2025-39964 case shows why the point at which the clock starts matters. Inclusion in KEV can accelerate a response that should already have been considered when the corresponding security update was published.

The Second AF_ALG Problem Arrived With AI Assistance

The AF_ALG subsystem appeared again in another investigation during 2026. Theori identified CVE-2026-31431, known as Copy Fail, using Xint Code, an artificial intelligence-assisted analysis tool.

According to the research cited by OpenSecurity, the flaw had been present since 2017 and allowed an unprivileged local user to perform a controlled four-byte write into the page cache. The vulnerability could be used as part of an exploitation chain to obtain elevated privileges and escape certain container environments.

The patch reached the mainline kernel on April 1, 2026, and the vulnerability was publicly disclosed on April 29. The exploit published by Theori was 732 bytes of Python and could run without modifications on several affected distributions.

The difference from CVE-2025-39964 lies in the timeline. With Copy Fail, discovery, remediation, and disclosure took place over a relatively short period. In the earlier case, the fix already existed when CISA added the CVE to KEV approximately a year later.

For administrators, the practical consequence is straightforward: waiting for a vulnerability to enter KEV is not a kernel update strategy. Linux distributions maintain their own security databases and publish patched packages for supported versions.

Updating the kernel also does not necessarily mean installing an individual patch for every CVE. Stable releases bundle multiple changes and fixes, so maintaining a supported branch and applying the updates supplied by the distribution is part of normal system maintenance.

The volume of vulnerabilities also makes manual management difficult. OpenSecurity’s research points to more than 2,000 records associated with the kernel during September 2026 in data from the National Vulnerability Database (NVD), although some of those records were still awaiting a definitive severity assessment.

Artificial intelligence adds another variable. Tools capable of analyzing large amounts of code can reduce the cost of locating certain classes of bugs. CISA has also linked the evolution of artificial intelligence capabilities in its new directive to the need to reduce response times for exploitable vulnerabilities.

For Linux, the CVE-2025-39964 case is ultimately less about the $113,337 figure than about the timing of software security. An exploit can demonstrate that a vulnerability is technically exploitable, while a catalog such as KEV can later raise its response priority. Between those two points, there may be a period in which the patch has already been available for months.

Frequently Asked Questions

What is CVE-2025-39964?

It is a race-condition vulnerability in the Linux kernel related to AF_ALG, the kernel’s cryptographic interface. The issue affects the handling of concurrent writes to the same socket.

How much did Google pay for the exploit?

Google’s kernelCTF program awarded a $113,337 bounty for the exploit developed from the vulnerability discovered by Muhammad Alifa Ramdhan.

When did CISA add CVE-2025-39964 to KEV?

CISA added the CVE to its Known Exploited Vulnerabilities catalog on September 18, 2026, and set September 21 as the deadline specified in the entry.

What is Copy Fail?

Copy Fail is the name associated with CVE-2026-31431, another vulnerability related to AF_ALG. It was discovered using an artificial intelligence-assisted analysis tool and was publicly disclosed in April 2026.

vía: Administración de sistemas

Scroll to Top