Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Linux Kernel Vulnerability Allows Root Access and Container Escape

Linux Kernel Vulnerability Allows Root Access and Container Escape

Posted on September 25, 2026 By CWS

A critical Linux kernel vulnerability, known to exist for 14 years, has been identified, allowing local users to gain root access and escape from Docker containers. This flaw, rooted in the AF_ALG userspace cryptographic interface, poses significant risks by enabling unauthorized privilege escalation.

Understanding the AF_ALG Flaw

The vulnerability arises from unsafe concurrent writes within the AF_ALG interface, primarily used for cryptographic operations like AES encryption. Local unprivileged processes can exploit this interface, creating an attractive target for attackers and researchers focusing on kernel security.

Discovered by Muhammad Alifa Ramdhan at STAR Labs during a kernel code audit for Google’s kernelCTF program, the flaw has been developed into a reliable local privilege escalation exploit. The research, conducted with Bing-Jhong Billy Jheng, secured a $113,337 reward for its submission.

Security Implications and Exploit Details

Listed by CISA as CVE-2025-39964, this vulnerability has been reported as actively exploited, underlining the urgency for patching. The core issue is a race condition in the AF_ALG’s sendmsg() handling, where concurrent writes can occur, leading to unauthorized modifications.

By manipulating the timing, attackers can maintain a merge flag while lacking valid entries in the final scatter-gather list, facilitating out-of-bounds access. This access can influence heap data, allowing attackers to craft a usercopy oracle and attain an arbitrary kernel write primitive.

Patch and Prevention Measures

Upstream Linux developers have addressed this flaw by implementing exclusive write ownership for AF_ALG contexts. The patch introduces a check on the write state, preventing concurrent writes from altering shared socket states.

Administrators are urged to update their systems with the patched kernel versions promptly. These include Linux 5.10.246, 5.15.195, 6.1.155, 6.6.109, 6.12.50, and 6.16.10. This update is crucial for environments where untrusted code execution is possible, such as shared Linux infrastructure and container hosts.

In conclusion, addressing this long-standing Linux kernel vulnerability is essential to maintaining system security and preventing potential exploits. Organizations should prioritize applying these patches to protect their infrastructures effectively.

Cyber Security News Tags:AF_ALG, CISA, container escape, CVE-2025-39964, Cybersecurity, Docker escape, kernel exploitation, kernel vulnerability, Linux, Linux patch, privilege escalation, root access, security patch, security research, system security

Post navigation

Previous Post: OnePlus Vulnerabilities Allow Root Access via OxygenOS
Next Post: Hackers Exploit Samsung Flaw to Install Cryptominer

Related Posts

RingReaper Malware Attacking Linux Servers Evading EDR Solutions RingReaper Malware Attacking Linux Servers Evading EDR Solutions Cyber Security News
GitLab Patches Multiple Vulnerabilities That Enables Denial Of Service And SSRF Attacks GitLab Patches Multiple Vulnerabilities That Enables Denial Of Service And SSRF Attacks Cyber Security News
SloppyRAT Malware: New Tactics via ClickFix Uncovered SloppyRAT Malware: New Tactics via ClickFix Uncovered Cyber Security News
Windows Docker Desktop Vulnerability Leads to Full Host Compromise Windows Docker Desktop Vulnerability Leads to Full Host Compromise Cyber Security News
New TamperedChef Malware Leverages Productivity Tools to Gain Access and Exfiltrate Sensitive Data New TamperedChef Malware Leverages Productivity Tools to Gain Access and Exfiltrate Sensitive Data Cyber Security News
INJ3CTOR3 Hackers Exploit FreePBX Systems with Six-Layer Tactics INJ3CTOR3 Hackers Exploit FreePBX Systems with Six-Layer Tactics Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Salmon Launches EVI to Secure AI and Autonomous Systems
  • Sauron Loader Malware Evades Detection with New Tactics
  • AI-Driven Botnet Targets Unsecured Docker Servers
  • Hackers Exploit Samsung Flaw to Install Cryptominer
  • Linux Kernel Vulnerability Allows Root Access and Container Escape

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Salmon Launches EVI to Secure AI and Autonomous Systems
  • Sauron Loader Malware Evades Detection with New Tactics
  • AI-Driven Botnet Targets Unsecured Docker Servers
  • Hackers Exploit Samsung Flaw to Install Cryptominer
  • Linux Kernel Vulnerability Allows Root Access and Container Escape

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark