PT-2026-27766 · Unknown · Cryptodev-Linux

·

CVE-2026-28529

·

Published

2026-03-25

·

Updated

2026-08-17

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions cryptodev-linux versions prior to 1.15
Description A page reference handling flaw exists in the get userbuf() function of the /dev/crypto device driver. This issue allows local users to trigger use-after-free conditions, which occurs when a program continues to use a pointer after it has been freed. Attackers with access to the /dev/crypto interface can repeatedly decrement reference counts of controlled pages to achieve local privilege escalation.
Recommendations Update to a version newer than 1.14. Restrict access to the /dev/crypto interface to minimize the risk of exploitation.

Exploit

Fix

LPE

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28529

Affected Products

Cryptodev-Linux