Wind River Support Network

HomeDefectsLIN1024-12635
Fixed

LIN1024-12635 : Security Advisory - linux - CVE-2025-39931

Created: Oct 10, 2025    Updated: Oct 22, 2025
Resolved Date: Oct 22, 2025
Found In Version: 10.24.33.1
Fix Version: 10.24.33.13
Severity: Standard
Applicable for: Wind River Linux LTS 24
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:[EOL][EOL]crypto: af_alg - Set merge to zero early in af_alg_sendmsg[EOL][EOL]If an error causes af_alg_sendmsg to abort, ctx->merge may contain[EOL]a garbage value from the previous loop.  This may then trigger a[EOL]crash on the next entry into af_alg_sendmsg when it attempts to do[EOL]a merge that can't be done.[EOL][EOL]Fix this by setting ctx->merge to zero near the start of the loop.

CVEs


Live chat
Online