CVE-2026-43077

MEDIUM

crypto: algif_aead - Fix minimum RX size check for decryption

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Fix minimum RX size check for decryption The check for the minimum receive buffer size did not take the tag size into account during decryption. Fix this by adding the required extra length.

Scores

CVSS v3 5.5
EPSS 0.0001
EPSS Percentile 2.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (21)
Linux/Linux < 4.14
Linux/Linux 4.14
Linux/Linux 5.10.254 - 5.10.*
Linux/Linux 5.15.204 - 5.15.*
Linux/Linux 6.1.170 - 6.1.*
Linux/Linux 6.12.83 - 6.12.*
Linux/Linux 6.18.24 - 6.18.*
Linux/Linux 6.19.14 - 6.19.*
Linux/Linux 6.6.136 - 6.6.*
Linux/Linux 7.0
... and 11 more
Published May 06, 2026
Tracked Since May 06, 2026