Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

[CVE-2025-39964] How I Found a $113,337 AF_ALG Linux Local Privilege Escalation Before Copy Fail

Summary

Write-up of CVE-2025-39964, an AF_ALG race condition in the Linux kernel enabling an out-of-bounds scatterlist write. The exploit overwrites core_pattern for root and a Docker container escape.
CVE
CVE-2025-39964
Published
Collected

original ↗