A retrospective on CVE-2025-39964, an AF_ALG race condition I found in 2025 before Copy Fail drew attention to the same subsystem. I explain the out-of-bounds scatterlist access, the usercopy oracle, and the exploit that achieved root and a Docker container escape.