In the Linux kernel, the following vulnerability has been resolved:
crypto: afalg - Set merge to zero early in afalg_sendmsg
If an error causes afalgsendmsg to abort, ctx->merge may contain a garbage value from the previous loop. This may then trigger a crash on the next entry into afalgsendmsg when it attempts to do a merge that can't be done.
Fix this by setting ctx->merge to zero near the start of the loop.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/39xxx/CVE-2025-39931.json",
"cna_assigner": "Linux"
}