In the Linux kernel, the following vulnerability has been resolved:
crypto: skcipher - Fix reqsize handling
Commit afddce13ce81d ("crypto: api - Add reqsize to crypto_alg") introduced cra_reqsize field in crypto_alg struct to replace type specific reqsize fields. It looks like this was introduced specifically for ahash and acomp from the commit description as subsequent commits add necessary changes in these alg frameworks.
However, this is being recommended for use in all crypto algs [1] instead of setting reqsize using crypto_*_set_reqsize(). Using cra_reqsize in skcipher algorithms, hence, causes memory corruptions and crashes as the underlying functions in the algorithm framework have not been updated to set the reqsize properly from cra_reqsize. [2]
Add proper set_reqsize calls in the skcipher init function to properly initialize reqsize for these algorithms in the framework.
[1]: https://lore.kernel.org/linux-crypto/[email protected]/ [2]: https://gist.github.com/Pratham-T/24247446f1faf4b7843e4014d5089f6b
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ubuntu | — | Upgrade linux-image-oem-6.17Upgrade linux-image-6.17.0-1007-gcpUpgrade linux-image-azure-6.17Upgrade linux-image-generic-6.17Upgrade linux-image-oracle-64k-6.17Upgrade linux-image-gcp-64k-6.17Upgrade linux-image-6.17.0-1007-awsUpgrade linux-image-gcp-6.17Upgrade linux-image-aws-64k-6.17Upgrade linux-image-6.17.0-1007-gcp-64kUpgrade linux-image-6.17.0-1007-oracle-64kUpgrade linux-image-6.17.0-1008-raspiUpgrade linux-image-generic-64k-6.17Upgrade linux-image-6.17.0-1007-aws-64kUpgrade linux-image-gcp-64kUpgrade linux-image-6.17.0-14-genericUpgrade linux-image-azureUpgrade linux-image-oracle-6.17Upgrade linux-image-6.17.0-1008-azureUpgrade linux-image-awsUpgrade linux-image-raspiUpgrade linux-image-oracleUpgrade linux-image-generic-64kUpgrade linux-image-6.17.0-1007-oracleUpgrade linux-image-gcpUpgrade linux-image-raspi-6.17Upgrade linux-image-virtual-6.17Upgrade linux-image-virtualUpgrade linux-image-genericUpgrade linux-image-aws-64kUpgrade linux-image-6.17.0-14-generic-64kUpgrade linux-image-realtimeUpgrade linux-image-oracle-64kUpgrade linux-image-realtime-6.17Upgrade linux-image-6.17.0-1011-oemUpgrade linux-image-aws-6.17Upgrade linux-image-6.17.0-1006-realtime | Feb 13, 2026 | Feb 12, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub