CVE-2025-39964

Alta7.8Pubblicata il 13 ottobre 2025

Nel kernel Linux è stata risolta la seguente vulnerabilità: crypto: af_alg - Impedisci scritture concorrenti in af_alg_sendmsg Eseguire due scritture sullo stesso socket af_alg è scorretto, poiché i dati verrebbero intercalati in modo imprevedibile. Inoltre, le scritture concorrenti possono creare incoerenze nello stato interno del socket. Impedire questa situazione aggiungendo un nuovo campo ctx->write che indica la proprietà esclusiva per la scrittura.

Sfruttata attivamente

  • Nel catalogo CISA delle vulnerabilità sfruttate dal 18 set 2026
  • Le agenzie federali statunitensi devono correggerla entro il 21 set 2026 (direttiva BOD 22-01)
  • Primo attacco osservato 339 giorni dopo la divulgazione

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Fonte: CISA KEV · 18 set 2026

Punteggio CVSS7.8 / 10CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Tipo di debolezza (CWE)CWE-362, CWE-362
Vendorlinux, siemens

Prodotti coinvolti

VendorProdottoVersioni
linuxlinux kernel< 5.10.245
siemenssimatic s7-1500 cpu 1518-4 pn\/dp mfp firmware
siemenssimatic s7-1500 cpu 1518-4 pn\/dp mfp
siemenssimatic s7-1500 cpu 1518f-4 pn\/dp mfp firmware
siemenssimatic s7-1500 cpu 1518f-4 pn\/dp mfp

Articoli correlati

This product uses the NVD API but is not endorsed or certified by the NVD.

La descrizione tecnica è una nostra traduzione del testo originale NVD, in inglese.

Database CVE