CVE-2026-43077

MEDIUM EPSS 2.4%
Published May 6, 20261mo ago · Modified Jun 17, 20261w ago
5.5 CVSS 3.1
Medium
Find Similar
Published May 6, 2026 1mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Fix minimum RX size check for decryption The check for the minimum receive buffer size did not take the tag size into account during decryption. Fix this by adding the required extra length.

CVSS Details

Base Score
5.5
Exploitability
1.8
Impact
3.6
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
2.4% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Affected Products 15

VendorProductVersionRange
linuxlinux_kernel*≥4.14.1  –  <5.10.254
linuxlinux_kernel*≥5.11  –  <5.15.204
linuxlinux_kernel*≥5.16  –  <6.1.170
linuxlinux_kernel*≥6.2  –  <6.6.136
linuxlinux_kernel*≥6.7  –  <6.12.83
linuxlinux_kernel*≥6.13  –  <6.18.24
linuxlinux_kernel*≥6.19  –  <6.19.14
linuxlinux_kernel4.14any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any
linuxlinux_kernel7.0any

References 8

  • git.kernel.org https://git.kernel.org/stable/c/1c76b5675119f694458293a2a81f40731c69bd32
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/3afdc15d6173614d7d834517d9b65e7aa5a08548
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/3d14bd48e3a77091cbce637a12c2ae31b4a1687c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/74a66fdb5282d89e348b00c42cfca3a936946d94
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/78cea133daf721698876e56135049a96d39d610a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/af2fa2fbbced26129813274b8b3f7705f280e174
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e86ab1e5661386a874fbb8551f0c04b8e9f8ad22
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fd427dd84f224309afbcc2cb67c7bb770a01265c
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/1c76b5675119f694458293a2a81f40731c69bd32
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/3afdc15d6173614d7d834517d9b65e7aa5a08548
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/3d14bd48e3a77091cbce637a12c2ae31b4a1687c
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/74a66fdb5282d89e348b00c42cfca3a936946d94
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/78cea133daf721698876e56135049a96d39d610a
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/af2fa2fbbced26129813274b8b3f7705f280e174
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/e86ab1e5661386a874fbb8551f0c04b8e9f8ad22
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/fd427dd84f224309afbcc2cb67c7bb770a01265c
    Patch