Junglewise Threat Intelligence

CVE-2025-39931: Linux Kernel denial of service in crypto af_alg_sendmsg

CVE-2025-39931 · Severity: medium · CVSS 5.5 · Published 2025-10-04

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's cryptographic services could allow a local user to crash the system. The issue occurs when the kernel processes certain encryption requests from applications, leading to a system instability or a complete halt (denial of service). This could disrupt business operations and affect the availability of services running on the impacted Linux systems.

Technical details

A vulnerability exists in the Linux kernel's AF_ALG (crypto) socket interface due to the use of an uninitialized resource (CWE-908). Specifically, in the `af_alg_sendmsg` function, if an error occurs that causes the function to abort, the `ctx->merge` variable may retain a 'garbage' value from a previous loop iteration. A subsequent call to `af_alg_sendmsg` may then attempt to perform a merge operation based on this invalid value, resulting in a kernel crash. This is a local attack vector requiring low privileges and no user interaction. The issue has been resolved by ensuring `ctx->merge` is explicitly set to zero at the beginning of the message processing loop.

Affected products

  • Linux Linux Kernel 2.6.38 to 6.16.9

Timeline

  • 2025-09-16: patched: Initial patch authored by Herbert Xu
  • 2025-10-04: advisory: CVE published by NVD

References

Related threats