CVE-2025-39964 is a local privilege-escalation race in the AF_ALG cryptographic socket path that a researcher discovered in 2025 and exploited to gain root and escape a Docker container, earning a $113,337 reward after responsible disclosure. The bug arises when two concurrent writers to the same AF_ALG opfd leave the context's merge flag set while the final scatterlist structure has cur equal to zero, causing the kernel to compute a negative index (sg -1) and perform an out-of-bounds scatterlist access. Controlled metadata in the preceding heap object turns that access into a usercopy oracle and an arbitrary kernel write; the exploit chain uses that write to overwrite core_pattern and execute code as root. The vulnerability predates wider attention to AF_ALG (e.g., Copy Fail) and was fixed upstream by preventing concurrent writes to a single AF_ALG socket.
Technically, AF_ALG accumulates input across sendmsg() calls using a context per accepted socket that holds a linked list of af_alg_tsgl objects, each with a cur counter and an array of scatterlist entries. sendmsg() with MSG_MORE lets the kernel append data into the last scatterlist entry rather than allocating a new one; when allocation and merge logic race, cur can be observed as zero while code still indexes the “last” entry, producing the out-of-bounds read/write. The flaw leverages memcpy_from_msg() behavior for the usercopy oracle and heap layout manipulation to convert the OOB access into a reliable arbitrary write, which the exploit uses to escalate privileges.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.