In the Linux kernel, the following vulnerability has been resolved:
crypto: hisilicon/zip - fix mismatch in get/set sgl_sge_nr
KASAN reported this Bug:
[17619.659757] BUG: KASAN: global-out-of-bounds in param_get_int+0x34/0x60 [17619.673193] Read of size 4 at addr fffff01332d7ed00 by task read_all/1507958 ... [17619.698934] The buggy address belongs to the variable: [17619.708371] sgl_sge_nr+0x0/0xffffffffffffa300 [hisi_zip]
There is a mismatch in hisi_zip when get/set the variable sgl_sge_nr. The type of sgl_sge_nr is u16, and get/set sgl_sge_nr by param_get/set_int.
Replacing param_get/set_int to param_get/set_ushort can fix this bug.
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Dec 31, 2025 | Dec 31, 2025 |
| Ubuntu | — | Upgrade linux-lowlatencyUpgrade linux-nvidiaUpgrade linux-azure-5.15Upgrade linuxUpgrade linux-ibmUpgrade linux-gcpUpgrade linux-gkeopUpgrade linux-oracle-5.15Upgrade linux-realtimeUpgrade linux-intel-iotg-5.15Upgrade linux-bluefieldUpgrade linux-raspiUpgrade linux-awsUpgrade linux-aws-5.15Upgrade linux-riscv-5.15Upgrade linux-azureUpgrade linux-oracleUpgrade linux-gcp-5.15Upgrade linux-hwe-5.15Upgrade linux-lowlatency-hwe-5.15Upgrade linux-gkeUpgrade linux-intel-iotgUpgrade linux-kvm | Jan 6, 2026 | Jan 2, 2026 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | May 27, 2026 | Dec 30, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub