PT-2026-98529 · Linux · Linux Kernel

CVE-2026-97589

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists in the s390 crypto implementation where the do one request callback returns a negative error code instead of 0 after a request is explicitly completed by crypto finalize hash request() or crypto finalize skcipher request(). This causes the crypto engine to incorrectly assume the driver failed to take ownership, triggering a second completion via crypto request complete(), which leads to a double completion. This behavior is present in phmac s390.c and paes s390.c within the phmac do one request() function and the four paes do one request callbacks (ecb, cbc, ctr, xts).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-97589

Affected Products

Linux Kernel