In the Linux kernel, the following vulnerability has been resolved:
crypto: comp - Use same definition of context alloc and free ops
In commit 42d9f6c77479 ("crypto: acomp - Move scomp stream allocation code into acomp"), the crypto_acomp_streams struct was made to rely on having the alloc_ctx and free_ctx operations defined in the same order as the scomp_alg struct. But in that same commit, the alloc_ctx and free_ctx members of scomp_alg may be randomized by structure layout randomization, since they are contained in a pure ops structure (containing only function pointers). If the pointers within scomp_alg are randomized, but those in crypto_acomp_streams are not, then the order may no longer match. This fixes the problem by removing the union from scomp_alg so that both crypto_acomp_streams and scomp_alg will share the same definition of alloc_ctx and free_ctx, ensuring they will always have the same layout.
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Oct 28, 2025 |
| Ubuntu | — | Upgrade linux-image-6.17.0-1007-oracleUpgrade linux-image-oem-6.17Upgrade linux-image-virtual-6.17Upgrade linux-image-awsUpgrade linux-image-aws-64kUpgrade linux-image-raspi-6.17Upgrade linux-image-6.17.0-1007-awsUpgrade linux-image-azureUpgrade linux-image-generic-64kUpgrade linux-image-realtime-6.17Upgrade linux-image-6.17.0-1006-realtimeUpgrade linux-image-gcp-64kUpgrade linux-image-6.17.0-1007-gcpUpgrade linux-image-aws-64k-6.17Upgrade linux-image-gcp-6.17Upgrade linux-image-oracle-64kUpgrade linux-image-generic-64k-6.17Upgrade linux-image-gcpUpgrade linux-image-raspiUpgrade linux-image-realtimeUpgrade linux-image-6.17.0-1007-oracle-64kUpgrade linux-image-gcp-64k-6.17Upgrade linux-image-6.17.0-14-generic-64kUpgrade linux-image-generic-6.17Upgrade linux-image-genericUpgrade linux-image-azure-6.17Upgrade linux-image-aws-6.17Upgrade linux-image-oracle-6.17Upgrade linux-image-6.17.0-14-genericUpgrade linux-image-6.17.0-1011-oemUpgrade linux-image-6.17.0-1007-aws-64kUpgrade linux-image-virtualUpgrade linux-image-oracle-64k-6.17Upgrade linux-image-6.17.0-1008-raspiUpgrade linux-image-6.17.0-1008-azureUpgrade linux-image-oracleUpgrade linux-image-6.17.0-1007-gcp-64k | Feb 13, 2026 | Feb 12, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub