CVE-2026-46033

HIGH EPSS 2.6%
Published May 27, 20261mo ago · Modified Jun 17, 20261w ago
7.1 CVSS 3.1
High
Find Similar
Published May 27, 2026 1mo ago
Last Modified Jun 17, 2026 1w ago

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - reject short ahash digests during instance creation authencesn requires either a zero authsize or an authsize of at least 4 bytes because the ESN encrypt/decrypt paths always move 4 bytes of high-order sequence number data at the end of the authenticated data. While crypto_authenc_esn_setauthsize() already rejects explicit non-zero authsizes in the range 1..3, crypto_authenc_esn_create() still copied auth->digestsize into inst->alg.maxauthsize without validating it. The AEAD core then initialized the tfm's default authsize from that value. As a result, selecting an ahash with digest size 1..3, such as cbcmac(cipher_null), exposed authencesn instances whose default authsize was invalid even though setauthsize() would have rejected the same value. AF_ALG could then trigger the ESN tail handling with a too-short tag and hit an out-of-bounds access. Reject authencesn instances whose ahash digest size is in the invalid non-zero range 1..3 so that no tfm can inherit an unsupported default authsize.

CVSS Details

Base Score
7.1
Exploitability
1.8
Impact
5.2
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity None
Availability High

Threat Intelligence

EPSS Exploit Probability
2.6% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-125 Out-of-bounds Read Memory Safety

Affected Products 8

VendorProductVersionRange
linuxlinux_kernel*≥4.11  –  <5.10.258
linuxlinux_kernel*≥5.11  –  <5.15.209
linuxlinux_kernel*≥5.16  –  <6.1.175
linuxlinux_kernel*≥6.2  –  <6.6.140
linuxlinux_kernel*≥6.7  –  <6.12.86
linuxlinux_kernel*≥6.13  –  <6.18.27
linuxlinux_kernel*≥6.19  –  <7.0.4
linuxlinux_kernel7.1any

References 8

  • git.kernel.org https://git.kernel.org/stable/c/2f31cd1e64a079c845bca31d2da7b3c90a311726
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5db6ef9847717329f12c5ea8aba7e9f588a980c0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/67f1f0933cc3d78dde222842bcad2778ec7a0b88
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/77f59fb2d3aa33e90ec6cbbf45dcfb20ab82b1a9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9aff81e8217e9de2929084b03b3c7f81988c112b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b42821c15445f93daea3e76ada682b2b7181c476
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b69933e97efea238ebbfcf70c2b1be1cd03f13e3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d4c6a6d08e70bb1083c7c405fc7faacbf19aebc0
    Patch

Remediation

  • git.kernel.org https://git.kernel.org/stable/c/2f31cd1e64a079c845bca31d2da7b3c90a311726
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/5db6ef9847717329f12c5ea8aba7e9f588a980c0
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/67f1f0933cc3d78dde222842bcad2778ec7a0b88
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/77f59fb2d3aa33e90ec6cbbf45dcfb20ab82b1a9
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/9aff81e8217e9de2929084b03b3c7f81988c112b
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b42821c15445f93daea3e76ada682b2b7181c476
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/b69933e97efea238ebbfcf70c2b1be1cd03f13e3
    Patch
  • git.kernel.org https://git.kernel.org/stable/c/d4c6a6d08e70bb1083c7c405fc7faacbf19aebc0
    Patch