VulnerabilityAnalyzed
CVE-2026-43077
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Fix minimum RX size check for decryption The check for the minimum receive buffer size did not take the tag size into account during decryption.
MEDIUM 5.5EPSS 0.12%
Does this matter?
Lower severity and a low EPSS score (0.12%). Track it; it rarely justifies an emergency change on its own.
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Fix minimum RX size check for decryption The check for the minimum receive buffer size did not take the tag size into account during decryption. Fix this by adding the required extra length.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.12% probability · 2th percentile
- CISA KEV
- Not listed
- Affected
- linux/linux kernel
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/1c76b5675119f694458293a2a81f40731c69bd32Patch
- https://git.kernel.org/stable/c/3afdc15d6173614d7d834517d9b65e7aa5a08548Patch
- https://git.kernel.org/stable/c/3d14bd48e3a77091cbce637a12c2ae31b4a1687cPatch
- https://git.kernel.org/stable/c/74a66fdb5282d89e348b00c42cfca3a936946d94Patch
- https://git.kernel.org/stable/c/78cea133daf721698876e56135049a96d39d610aPatch
- https://git.kernel.org/stable/c/af2fa2fbbced26129813274b8b3f7705f280e174Patch
- https://git.kernel.org/stable/c/e86ab1e5661386a874fbb8551f0c04b8e9f8ad22Patch
- https://git.kernel.org/stable/c/fd427dd84f224309afbcc2cb67c7bb770a01265cPatch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.