Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Linux Kernel Vulnerability Allows Root Access and Container Escape

Linux Kernel Vulnerability Allows Root Access and Container Escape

Posted on September 25, 2026 By CWS

A critical Linux kernel vulnerability, known to exist for 14 years, has been identified, allowing local users to gain root access and escape from Docker containers. This flaw, rooted in the AF_ALG userspace cryptographic interface, poses significant risks by enabling unauthorized privilege escalation.

Understanding the AF_ALG Flaw

The vulnerability arises from unsafe concurrent writes within the AF_ALG interface, primarily used for cryptographic operations like AES encryption. Local unprivileged processes can exploit this interface, creating an attractive target for attackers and researchers focusing on kernel security.

Discovered by Muhammad Alifa Ramdhan at STAR Labs during a kernel code audit for Google’s kernelCTF program, the flaw has been developed into a reliable local privilege escalation exploit. The research, conducted with Bing-Jhong Billy Jheng, secured a $113,337 reward for its submission.

Security Implications and Exploit Details

Listed by CISA as CVE-2025-39964, this vulnerability has been reported as actively exploited, underlining the urgency for patching. The core issue is a race condition in the AF_ALG’s sendmsg() handling, where concurrent writes can occur, leading to unauthorized modifications.

By manipulating the timing, attackers can maintain a merge flag while lacking valid entries in the final scatter-gather list, facilitating out-of-bounds access. This access can influence heap data, allowing attackers to craft a usercopy oracle and attain an arbitrary kernel write primitive.

Patch and Prevention Measures

Upstream Linux developers have addressed this flaw by implementing exclusive write ownership for AF_ALG contexts. The patch introduces a check on the write state, preventing concurrent writes from altering shared socket states.

Administrators are urged to update their systems with the patched kernel versions promptly. These include Linux 5.10.246, 5.15.195, 6.1.155, 6.6.109, 6.12.50, and 6.16.10. This update is crucial for environments where untrusted code execution is possible, such as shared Linux infrastructure and container hosts.

In conclusion, addressing this long-standing Linux kernel vulnerability is essential to maintaining system security and preventing potential exploits. Organizations should prioritize applying these patches to protect their infrastructures effectively.

Cyber Security News Tags:AF_ALG, CISA, container escape, CVE-2025-39964, Cybersecurity, Docker escape, kernel exploitation, kernel vulnerability, Linux, Linux patch, privilege escalation, root access, security patch, security research, system security

Post navigation

Previous Post: OnePlus Vulnerabilities Allow Root Access via OxygenOS
Next Post: Hackers Exploit Samsung Flaw to Install Cryptominer

Related Posts

Data Breach at Pokémon Center: Customer Details Exposed Data Breach at Pokémon Center: Customer Details Exposed Cyber Security News
VECT 2.0 Ransomware: A Destructive Threat to Data VECT 2.0 Ransomware: A Destructive Threat to Data Cyber Security News
Hackers Leverage Built-in MacOS Protection Features to Deploy Malware Hackers Leverage Built-in MacOS Protection Features to Deploy Malware Cyber Security News
Hackers Attacking IT Admins by Poisoning SEO to Move Malware on Top of Search Results Hackers Attacking IT Admins by Poisoning SEO to Move Malware on Top of Search Results Cyber Security News
Alleged Ransomware Attack on Apple’s Second-Largest Manufacturer Luxshare Alleged Ransomware Attack on Apple’s Second-Largest Manufacturer Luxshare Cyber Security News
LocalGPT: Secure AI Assistant Built with Rust LocalGPT: Secure AI Assistant Built with Rust Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • TWEAKOS Malware Exploits Telegram for Account Theft
  • Salmon Launches EVI to Secure AI and Autonomous Systems
  • Sauron Loader Malware Evades Detection with New Tactics
  • AI-Driven Botnet Targets Unsecured Docker Servers
  • Hackers Exploit Samsung Flaw to Install Cryptominer

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • TWEAKOS Malware Exploits Telegram for Account Theft
  • Salmon Launches EVI to Secure AI and Autonomous Systems
  • Sauron Loader Malware Evades Detection with New Tactics
  • AI-Driven Botnet Targets Unsecured Docker Servers
  • Hackers Exploit Samsung Flaw to Install Cryptominer

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark