PT-2026-85721 · Linux · Linux

CVE-2026-80843

·

Publicado

2026-09-04

·

Atualizado

2026-09-04

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
xfrm: fix xfrm state construct() auth-trunc leak
attach auth trunc() can allocate x->aalg while leaving x->props.aalgo at zero when the selected auth algorithm has no sadb alg id. One real case is cmac(aes).
xfrm state construct() then treats !x->props.aalgo as "no auth algorithm attached yet" and calls attach auth(). That overwrites x->aalg and loses the first allocation. Any later failure or teardown only frees the replacement pointer.
Check whether x->aalg is already attached instead of inferring that state from x->props.aalgo.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-80843

Produtos afetados

Linux