14-Year-Old Linux Kernel Flaw Grants Root Access via AF_ALG Vulnerability
A critical vulnerability in the Linux kernel’s AF_ALG cryptographic socket interface, tracked as CVE-2025-39964, allows unprivileged local users to escalate privileges to root and escape Docker containers. The flaw, discovered in 2025 by security researcher Muhammad Alifa Ramdhan during an audit for Google’s kernelCTF program, stems from a race condition in concurrent sendmsg() operations, enabling out-of-bounds memory access and arbitrary kernel writes.
The vulnerability affects Linux kernels dating back to 2.6.38 (2011), predating a separate 2026 AF_ALG-related flaw ("Copy Fail"). AF_ALG, a userspace interface for the kernel’s Crypto API, allows applications to perform cryptographic operations (e.g., AES-CBC) via sockets without elevated permissions. The issue arises when multiple threads issue sendmsg() calls on the same AF_ALG socket, leading to a merge flag misconfiguration and an out-of-bounds read (sg[-1]). Exploiting this, attackers can manipulate heap metadata to achieve a write primitive, demonstrated in a proof-of-concept that overwrites the kernel’s core_pattern setting to execute arbitrary code as root.
The exploit’s impact extends to container escapes, as Docker containers share the host kernel. A successful attack grants root access on the underlying host. The flaw was patched in 2025 by preventing concurrent writers from accessing the same AF_ALG context, returning -EBUSY to subsequent attempts. Vendors have since released updates to mitigate the risk.
Source: https://cyberpress.org/14-year-old-linux-kernel-vulnerability/
Docker, Inc cybersecurity rating report: https://www.rankiteo.com/company/docker
Kernel Foundation - Master Linux Kernel & LDD cybersecurity rating report: https://www.rankiteo.com/company/linux-kernel-foundation
"id": "DOCLIN1790346460",
"linkid": "docker, linux-kernel-foundation",
"type": "Vulnerability",
"date": "1/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Technology/Software',
'type': 'Operating System'}],
'attack_vector': 'Local',
'date_detected': '2025',
'date_publicly_disclosed': '2025',
'date_resolved': '2025',
'description': 'A critical vulnerability in the Linux kernel’s AF_ALG '
'cryptographic socket interface, tracked as CVE-2025-39964, '
'allows unprivileged local users to escalate privileges to '
'root and escape Docker containers. The flaw stems from a race '
'condition in concurrent sendmsg() operations, enabling '
'out-of-bounds memory access and arbitrary kernel writes.',
'impact': {'operational_impact': 'Privilege escalation to root, container '
'escape',
'systems_affected': 'Linux kernels (2.6.38 and later), Docker '
'containers'},
'investigation_status': 'Resolved',
'lessons_learned': 'Importance of auditing legacy kernel interfaces for race '
'conditions and concurrency issues; need for timely '
'patching of critical vulnerabilities.',
'post_incident_analysis': {'corrective_actions': 'Patch to prevent concurrent '
'writers from accessing the '
'same AF_ALG context; vendor '
'updates for affected '
'kernels.',
'root_causes': 'Race condition in AF_ALG socket '
'interface due to concurrent '
'sendmsg() operations leading to '
'out-of-bounds memory access and '
'arbitrary kernel writes.'},
'recommendations': 'Apply kernel updates immediately; audit systems for signs '
'of exploitation; restrict container privileges where '
'possible.',
'references': [{'source': 'Google’s kernelCTF program'}],
'response': {'containment_measures': 'Patch released to prevent concurrent '
'writers from accessing the same AF_ALG '
'context',
'remediation_measures': 'Kernel updates released by vendors',
'third_party_assistance': 'Google’s kernelCTF program'},
'title': '14-Year-Old Linux Kernel Flaw Grants Root Access via AF_ALG '
'Vulnerability',
'type': 'Privilege Escalation',
'vulnerability_exploited': 'CVE-2025-39964 (Race condition in AF_ALG socket '
'interface)'}