PT-2026-43944 · Opensuse+3 · Opensuse Tumbleweed+3
CVE-2026-46077
·
Published
2026-05-27
·
Updated
2026-08-25
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
openSUSE Tumbleweed versions prior to kernel-devel-7.0.11-1.1
Description
An issue exists in the
atmel-tdes crypto component where the DMA output dma addr out is synced using dma sync single for device() instead of dma sync single for cpu() before being consumed by the CPU. On non-coherent platforms, using the incorrect sync direction can result in the CPU receiving stale cache data.Recommendations
Update to a version of the Linux kernel where the
dma sync single for cpu() function is correctly implemented for dma addr out.
Update openSUSE Tumbleweed to kernel-devel-7.0.11-1.1.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Ubuntu
Opensuse Tumbleweed