PT-2026-85710 · Linux · Linux

CVE-2026-80832

·

Publicado

2026-09-04

·

Atualizado

2026-09-04

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
crypto: qce - fix CCM AAD buffer underallocation
The AAD buffer allocated in qce aead ccm prepare buf assoclen() can be smaller than the length later programmed into the DMA scatterlist.
The allocation size is currently calculated as:
ALIGN(assoclen, 16) + MAX CCM ADATA HEADER LEN
while the DMA length is set to:
ALIGN(assoclen + adata header len, 16)
Since ALIGN() does not distribute over addition, the allocation can be smaller than the DMA length. For example, when assoclen = 32 and adata header len = 2:
allocation = ALIGN(32, 16) + 6 = 38 DMA length = ALIGN(32 + 2, 16) = 48
As a result, the QCE hardware can read beyond the allocated buffer while computing the CBC-MAC over the associated data. The extra bytes are folded into the authentication tag, resulting in an incorrect tag and causing CCM self-test failures such as:
alg: aead: ccm-aes-qce encryption test failed (wrong result) on test vector 8
Fix the allocation by adding the maximum possible AAD header length before alignment:
ALIGN(assoclen + MAX CCM ADATA HEADER LEN, 16)
This guarantees that the allocated buffer is large enough for the fully padded AAD data for all supported header sizes.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-80832

Produtos afetados

Linux