CVE 7.8 HIGH

crypto: af_alg – Fix page reassignment overflow in af_alg_pull_tsgl_CVE-2026-43078

7.8 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

In the Linux kernel, the following vulnerability has been resolved:

crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl

When page reassignment was added to af_alg_pull_tsgl the original
loop wasn't updated so it may try to reassign one more page than
necessary.

Add the check to the reassignment so that this does not happen.

Also update the comment which still refers to the obsolete offset
argument.

Basic Information

ID CVE-2026-43078
Source Linux
Published May 6, 2026 at 07:40
Modified May 8, 2026 at 12:40

Affected Product

Vendor Linux
Product Linux
Version e870456d8e7c8d57c059ea479b5aadbb55ff4c3a
Affected Versions Linux Linux e870456d8e7c8d57c059ea479b5aadbb55ff4c3a
Linux Linux e870456d8e7c8d57c059ea479b5aadbb55ff4c3a
Linux Linux e870456d8e7c8d57c059ea479b5aadbb55ff4c3a
Linux Linux e870456d8e7c8d57c059ea479b5aadbb55ff4c3a
Linux Linux e870456d8e7c8d57c059ea479b5aadbb55ff4c3a
Linux Linux e870456d8e7c8d57c059ea479b5aadbb55ff4c3a
Linux Linux e870456d8e7c8d57c059ea479b5aadbb55ff4c3a
Linux Linux e870456d8e7c8d57c059ea479b5aadbb55ff4c3a
Linux Linux 4.14

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.