CVE 7.8 HIGH

crypto: ccp – copy IV using skcipher ivsize_CVE-2026-53016

7.8 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

In the Linux kernel, the following vulnerability has been resolved:

crypto: ccp - copy IV using skcipher ivsize

AF_ALG rfc3686-ctr-aes-ccp requests pass an 8-byte IV to the driver.

ccp_aes_complete() restores AES_BLOCK_SIZE bytes into the caller's IV
buffer while RFC3686 skciphers expose an 8-byte IV, so the restore
overruns the provided buffer.

Use crypto_skcipher_ivsize() to copy only the algorithm's IV length.

Basic Information

ID CVE-2026-53016
Source Linux
Published Jun 24, 2026 at 16:29
Modified Jun 28, 2026 at 06:38

Affected Product

Vendor Linux
Product Linux
Version 2b789435d7f36ed918d92db647f3a2f3fec9bb1f
Affected Versions Linux Linux 2b789435d7f36ed918d92db647f3a2f3fec9bb1f
Linux Linux 2b789435d7f36ed918d92db647f3a2f3fec9bb1f
Linux Linux 2b789435d7f36ed918d92db647f3a2f3fec9bb1f
Linux Linux 2b789435d7f36ed918d92db647f3a2f3fec9bb1f
Linux Linux 2b789435d7f36ed918d92db647f3a2f3fec9bb1f
Linux Linux 2b789435d7f36ed918d92db647f3a2f3fec9bb1f
Linux Linux 2b789435d7f36ed918d92db647f3a2f3fec9bb1f
Linux Linux 2b789435d7f36ed918d92db647f3a2f3fec9bb1f
Linux Linux 3.14

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.