PT-2026-51910 · Linux+3 · Linux Kernel+3
CVE-2026-53016
·
Published
2026-04-16
·
Updated
2026-09-07
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel (affected versions not specified)
Description
A flaw exists in the cryptographic coprocessor (CCP) driver. When processing AF ALG rfc3686-ctr-aes-ccp requests, the
ccp aes complete() function restores more data than the allocated buffer for the Initialization Vector (IV) can hold. Because RFC3686 skciphers expose an 8-byte IV but the function restores AES BLOCK SIZE bytes, a buffer overrun occurs, leading to memory corruption within the kernel.Recommendations
Use
crypto skcipher ivsize() to ensure only the algorithm's IV length is copied.Exploit
Fix
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Linux Kernel
Rocky Linux
Ubuntu