CVE-2025-38079 is a double-free, slab use-after-free vulnerability in the Linux kernel's AF_ALG hash-socket implementation (crypto/algif_hash.c). It can occur when accept(2) is invoked on an algif_hash socket with MSG_MORE set and crypto_ahash_import fails: the sk2 socket object may be freed and then released again through af_alg_release. The flaw has existed since Linux 2.6.38.
Linux stable releases 5.4.294, 5.10.238, 5.15.185, 6.1.141, 6.6.93, 6.12.31, 6.14.9, and 6.15 include fixes. Red Hat also released RHSA-2025:14987 for RHEL 7 Extended Lifecycle Support, providing kernel version 3.10.0-1160.138.1.el7 for x86_64, s390x, ppc64, and ppc64le. Organizations should install the applicable kernel update and reboot affected hosts; upstream recommends updating to the latest stable kernel rather than cherry-picking the patch.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate-severity advisory RHSA-2025:14987 for Red Hat Enterprise Linux 7 Extended Lifecycle Support, fixing CVE-2025-38079 with kernel package 3.10.0-1160.138.1.el7. Affected systems must be rebooted after installation for the fix to take effect.
The issue was fixed in stable kernel releases 5.4.294, 5.10.238, 5.15.185, 6.1.141, 6.6.93, 6.12.31, 6.14.9, and 6.15. The kernel CVE team recommended updating to a current stable release rather than applying an individual commit.
The Linux kernel CVE team assigned CVE-2025-38079 to the AF_ALG hash-socket double-free vulnerability affecting the hash_accept path when crypto_ahash_import fails.
A flaw was introduced in Linux kernel 2.6.38 in crypto/algif_hash.c. Under an error condition in hash_accept, an algif_hash socket object can be freed twice, resulting in a slab use-after-free.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.