Description
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Amazon / amazon_linux
- Arista / cloudvision_agni2024.4.0 – 2025.2.2
- Arista / cloudvision_portal2024.2.0 – 2026.1.0
- Arista / netvisor_os7.1.0
- Arista / netvisor_os7.1.0 – 7.1.0
- Arista / netvisor_os7.1.0 – 7.1.0
- Arista / velocloud_edge4.5.0 – 6.4.1
- Arista / velocloud_gateway
- Arista / velocloud_orchestrator
- Canonical / Ubuntu Linux22.04 – 22.04
- Canonical / Ubuntu Linux16.04 – 16.04
- Canonical / Ubuntu Linux
- Canonical / Ubuntu Linux18.04 – 18.04
- Canonical / Ubuntu Linux20.04 – 20.04
- Canonical / Ubuntu Linux24.04 – 24.04
- Canonical / Ubuntu Linux25.10 – 25.10
- Canonical / Ubuntu Linux14.04 – 14.04
- debian / debian_linux13.0 – 13.0
- debian / debian_linux12.0 – 12.0
- debian / debian_linux11.0 – 11.0
- Linux / Linux72548b093ee38a6d4f2a19e6ef1948ae05c181f7 – 893d22e0135fa394db81df88697fba6032747667
- Linux / Linux72548b093ee38a6d4f2a19e6ef1948ae05c181f7 – 19d43105a97be0810edbda875f2cd03f30dc130c
- Linux / Linux72548b093ee38a6d4f2a19e6ef1948ae05c181f7 – 961cfa271a918ad4ae452420e7c303149002875b
- Linux / Linux72548b093ee38a6d4f2a19e6ef1948ae05c181f7 – 3115af9644c342b356f3f07a4dd1c8905cd9a6fc
- Linux / Linux72548b093ee38a6d4f2a19e6ef1948ae05c181f7 – 8b88d99341f139e23bdeb1027a2a3ae10d341d82
- Linux / Linux72548b093ee38a6d4f2a19e6ef1948ae05c181f7 – fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8
- Linux / Linux72548b093ee38a6d4f2a19e6ef1948ae05c181f7 – ce42ee423e58dffa5ec03524054c9d8bfd4f6237
- Linux / Linux72548b093ee38a6d4f2a19e6ef1948ae05c181f7 – a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5
- Linux / Linux4.14 – 4.14
- Linux / Linux0 – 4.14
- Linux / Linux5.10.254 – 5.10.*
- Linux / Linux5.15.204 – 5.15.*
- Linux / Linux6.1.170 – 6.1.*
- Linux / Linux6.6.137 – 6.6.*
- Linux / Linux6.12.85 – 6.12.*
- Linux / Linux6.18.22 – 6.18.*
- Linux / Linux6.19.12 – 6.19.*
- Linux / Linux7.0 – *
- Linux / Linux kernel7.0 – 7.0
- Linux / Linux kernel7.0 – 7.0
- Linux / Linux kernel4.14 – 5.10.254
- Linux / Linux kernel7.0 – 7.0
- Linux / Linux kernel7.0 – 7.0
- Linux / Linux kernel7.0 – 7.0
- Linux / Linux kernel7.0 – 7.0
- NixOS / nixos25.11
- openSUSE / Leap15.4 – 15.4
- openSUSE / Leap15.5 – 15.5
- openSUSE / Leap15.6 – 15.6
- openSUSE / Leap15.3 – 15.3
- RedHat / enterprise_linux9.0 – 9.0
- RedHat / enterprise_linux8.0 – 8.0
- RedHat / enterprise_linux10.1 – 10.1
- RedHat / enterprise_linux10.0 – 10.0
- RedHat / enterprise_linux_aus8.4 – 8.4
- RedHat / enterprise_linux_aus8.6 – 8.6
- RedHat / enterprise_linux_eus8.4 – 8.4
- RedHat / enterprise_linux_eus9.6 – 9.6
- RedHat / enterprise_linux_eus10.0 – 10.0
- RedHat / enterprise_linux_eus9.4 – 9.4
- RedHat / enterprise_linux_tus8.6 – 8.6
- RedHat / enterprise_linux_tus8.8 – 8.8
- RedHat / enterprise_linux_update_services_for_sap_solutions8.6 – 8.6
- RedHat / enterprise_linux_update_services_for_sap_solutions9.2 – 9.2
- RedHat / enterprise_linux_update_services_for_sap_solutions8.8 – 8.8
- RedHat / enterprise_linux_update_services_for_sap_solutions9.0 – 9.0
- RedHat / openshift_container_platform4.0 – 4.0
- RedHat / openshift_container_platform4.12 – 4.12.89
- Siemens / simatic_s7-1500_cpu_1518-4_pn/dp_mfp_firmware3.1.5 –
- Siemens / simatic_s7-1500_cpu_1518f-4_pn/dp_mfp_firmware3.1.5 –
- Siemens / simatic_s7-1500_tm_mfp_firmware1.1
- Siemens / siplus_s7-1500_cpu_1518-4_pn/dp_mfp_firmware3.1.5 –
- SUSE / basesystem_module15 – 15
- SUSE / basesystem_module15 – 15
- SUSE / basesystem_module15 – 15
- SUSE / basesystem_module15 – 15
- SUSE / basesystem_module15 – 15
- SUSE / basesystem_module15 – 15
- SUSE / basesystem_module15 – 15
- SUSE / caas_platform4.0 – 4.0
- SUSE / development_tools_module15 – 15
- SUSE / development_tools_module15 – 15
- SUSE / development_tools_module15 – 15
- SUSE / development_tools_module15 – 15
- SUSE / development_tools_module15 – 15
- SUSE / development_tools_module15 – 15
- SUSE / development_tools_module15 – 15
- SUSE / enterprise_storage6.0 – 6.0
- SUSE / enterprise_storage7.0 – 7.0
- SUSE / enterprise_storage7.1 – 7.1
- SUSE / legacy_module15 – 15
- SUSE / linux_enterprise_desktop15 – 15
- SUSE / linux_enterprise_desktop11 – 11
- SUSE / linux_enterprise_desktop12 – 12
- SUSE / linux_enterprise_desktop15 – 15
- SUSE / linux_enterprise_desktop15 – 15
- SUSE / linux_enterprise_desktop15 – 15
- SUSE / linux_enterprise_desktop15 – 15
- SUSE / linux_enterprise_desktop15 – 15
- SUSE / linux_enterprise_desktop15 – 15
- SUSE / linux_enterprise_high_availability_extension15 – 15
- SUSE / linux_enterprise_high_availability_extension15 – 15
- SUSE / linux_enterprise_high_availability_extension16.0 – 16.0
- SUSE / linux_enterprise_high_availability_extension15 – 15
- SUSE / linux_enterprise_high_performance_computing15.0 – 15.0
- SUSE / linux_enterprise_high_performance_computing15.0 – 15.0
- SUSE / linux_enterprise_high_performance_computing15.0 – 15.0
- SUSE / linux_enterprise_high_performance_computing15.0 – 15.0
- SUSE / linux_enterprise_high_performance_computing15.0 – 15.0
- SUSE / linux_enterprise_high_performance_computing15.0 – 15.0
- SUSE / linux_enterprise_high_performance_computing15.0 – 15.0
- SUSE / linux_enterprise_high_performance_computing15.0 – 15.0
- SUSE / linux_enterprise_high_performance_computing15.0 – 15.0
- SUSE / linux_enterprise_high_performance_computing15.0 – 15.0
- SUSE / linux_enterprise_high_performance_computing15.0 – 15.0
- SUSE / linux_enterprise_high_performance_computing15.0 – 15.0
- SUSE / linux_enterprise_high_performance_computing15.0 – 15.0
- SUSE / linux_enterprise_high_performance_computing15.0 – 15.0
- SUSE / linux_enterprise_high_performance_computing15.0 – 15.0
- SUSE / linux_enterprise_high_performance_computing15.0 – 15.0
- SUSE / linux_enterprise_high_performance_computing15.0 – 15.0
- SUSE / linux_enterprise_live_patching15 – 15
- SUSE / linux_enterprise_live_patching15 – 15
- SUSE / linux_enterprise_live_patching15 – 15
- SUSE / linux_enterprise_live_patching15 – 15
- SUSE / linux_enterprise_live_patching12 – 12
- SUSE / linux_enterprise_micro5.0 – 5.0
- SUSE / linux_enterprise_micro5.3 – 5.3
- SUSE / linux_enterprise_micro5.2 – 5.2
- SUSE / linux_enterprise_micro5.5 – 5.5
- SUSE / linux_enterprise_micro5.4 – 5.4
- SUSE / linux_enterprise_micro5.4 – 5.4
- SUSE / linux_enterprise_micro5.3 – 5.3
- SUSE / linux_enterprise_micro5.2 – 5.2
- SUSE / linux_enterprise_micro5.1 – 5.1
- SUSE / linux_enterprise_real_time15.0 – 15.0
- SUSE / linux_enterprise_real_time15.0 – 15.0
- SUSE / linux_enterprise_real_time15.0 – 15.0
- SUSE / linux_enterprise_real_time15.0 – 15.0
- SUSE / linux_enterprise_real_time15.0 – 15.0
- SUSE / linux_enterprise_real_time15.0 – 15.0
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server11 – 11
- SUSE / linux_enterprise_server11 – 11
- SUSE / linux_enterprise_server11 – 11
- SUSE / linux_enterprise_server12 – 12
- SUSE / linux_enterprise_server12 – 12
- SUSE / linux_enterprise_server12 – 12
- SUSE / linux_enterprise_server12 – 12
- SUSE / linux_enterprise_server12 – 12
- SUSE / linux_enterprise_server12 – 12
- SUSE / linux_enterprise_server12 – 12
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server15 – 15
- SUSE / linux_enterprise_server16.0 – 16.0
- SUSE / linux_enterprise_server16.0 – 16.0
- SUSE / linux_enterprise_server16.1 – 16.1
- SUSE / linux_enterprise_server16.1 – 16.1
- SUSE / linux_enterprise_workstation_extension15 – 15
- SUSE / linux_micro6.2 – 6.2
- SUSE / linux_micro6.1 – 6.1
- SUSE / linux_micro6.0 – 6.0
- SUSE / manager_proxy4.1 – 4.1
- SUSE / manager_proxy4.0 – 4.0
- SUSE / manager_proxy4.2 – 4.2
- SUSE / manager_proxy4.3 – 4.3
- SUSE / manager_retail_branch_server4.1 – 4.1
- SUSE / manager_retail_branch_server4.2 – 4.2
- SUSE / manager_retail_branch_server4.0 – 4.0
- SUSE / manager_retail_branch_server4.3 – 4.3
- SUSE / manager_server4.0 – 4.0
- SUSE / manager_server4.3 – 4.3
- SUSE / manager_server4.2 – 4.2
- SUSE / manager_server4.1 – 4.1
- SUSE / openstack_cloud9.0 – 9.0
- SUSE / openstack_cloud_crowbar9.0 – 9.0
- SUSE / public_cloud_module15 – 15
- SUSE / public_cloud_module15 – 15
- SUSE / realtime_module15 – 15
- SUSE / realtime_module15 – 15
- SUSE / realtime_module15 – 15
- SUSE / realtime_module15 – 15
- SUSE / realtime_module15 – 15
- VMware / velocloud_orchestrator
Exploits & proofs of concept
- nucleiCopy Fail - Linux Kernel Local Privilege Escalation via AF_ALGby ritikchaddha
References
- MISChttps://git.kernel.org/stable/c/893d22e0135fa394db81df88697fba6032747667
- MISChttps://git.kernel.org/stable/c/19d43105a97be0810edbda875f2cd03f30dc130c
- MISChttps://git.kernel.org/stable/c/961cfa271a918ad4ae452420e7c303149002875b
- MISChttps://git.kernel.org/stable/c/3115af9644c342b356f3f07a4dd1c8905cd9a6fc
- MISChttps://git.kernel.org/stable/c/8b88d99341f139e23bdeb1027a2a3ae10d341d82
- MISChttps://git.kernel.org/stable/c/fafe0fa2995a0f7073c1c358d7d3145bcc9aedd8
- MISChttps://git.kernel.org/stable/c/ce42ee423e58dffa5ec03524054c9d8bfd4f6237
- MISChttps://git.kernel.org/stable/c/a664bf3d603dc3bdcf9ae47cc21e0daec706d7a5
Updated 24m ago · 8 sources