CVE-2022-49260 (GCVE-0-2022-49260)
Vulnerability from cvelistv5
Published
2025-02-26 01:56
Modified
2026-08-05 08:54
Severity ?
Summary
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec - fix the aead software fallback for engine Due to the subreq pointer misuse the private context memory. The aead soft crypto occasionally casues the OS panic as setting the 64K page. Here is fix it.
Impacted products
Vendor Product Version
Linux Linux Version: 6c46a3297beae4ae2d22b26da5e091f058381c7c
Version: 6c46a3297beae4ae2d22b26da5e091f058381c7c
Version: 6c46a3297beae4ae2d22b26da5e091f058381c7c
Version: 6c46a3297beae4ae2d22b26da5e091f058381c7c
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/crypto/hisilicon/sec2/sec_crypto.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "40dba7c26e897c637e91312b35f664f1d4d0073c",
              "status": "affected",
              "version": "6c46a3297beae4ae2d22b26da5e091f058381c7c",
              "versionType": "git"
            },
            {
              "lessThan": "ef7b10f3cac7810ddcfd976304fd125aca33d144",
              "status": "affected",
              "version": "6c46a3297beae4ae2d22b26da5e091f058381c7c",
              "versionType": "git"
            },
            {
              "lessThan": "5c1149e2abe0b7489300736b8277b45b113de67f",
              "status": "affected",
              "version": "6c46a3297beae4ae2d22b26da5e091f058381c7c",
              "versionType": "git"
            },
            {
              "lessThan": "0a2a464f863187f97e96ebc6384c052cafd4a54c",
              "status": "affected",
              "version": "6c46a3297beae4ae2d22b26da5e091f058381c7c",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/crypto/hisilicon/sec2/sec_crypto.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.14"
            },
            {
              "lessThan": "5.14",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.33",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.16.*",
              "status": "unaffected",
              "version": "5.16.19",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.17.*",
              "status": "unaffected",
              "version": "5.17.2",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "5.18",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.33",
                  "versionStartIncluding": "5.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.16.19",
                  "versionStartIncluding": "5.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.17.2",
                  "versionStartIncluding": "5.14",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.18",
                  "versionStartIncluding": "5.14",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: hisilicon/sec - fix the aead software fallback for engine\n\nDue to the subreq pointer misuse the private context memory. The aead\nsoft crypto occasionally casues the OS panic as setting the 64K page.\nHere is fix it."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:N - On Kunpeng920 systems, hisi_sec GCM is selected as the rfc4106(gcm(aes)) child for IPsec ESP; inbound ESP decrypt with short elen (1\u20138) yields child cryptlen \u003c= authsize and hits the buggy soft-fallback path while processing attacker-controlled network packets.\nAC:L - The attacker fully controls ESP packet length (or AF_ALG cryptlen) and can reliably force the zero/short-length fallback; no race or external precondition beyond the presence of the affected accelerator is required.\nPR:N - ESP decrypt runs on SPI-matched packets before GCM tag authentication succeeds, so an unauthenticated remote peer can trigger the soft-fallback memory corruption; no local account or capability is required in the IPsec scenario.\nUI:N - Exploitation requires only attacker-sent ESP packets (or the attacker\u2019s own AF_ALG operations); no separate victim action is needed.\nS:U - Impact is kernel heap corruption and potential privilege escalation within the same host OS authority, not a VM/IOMMU/sandbox boundary escape.\nC:H - The bug treats undersized sec_req private context as a full aead_request plus software-GCM reqctx, causing a heap out-of-bounds write/type confusion that can be leveraged for arbitrary kernel memory disclosure.\nI:H - The same out-of-bounds write into adjacent heap objects provides a kernel memory corruption primitive usable for integrity compromise and control-flow hijacking.\nA:H - The commit documents OS panic on the affected 64K-page configuration, and heap corruption from the oversized soft-crypto request context can oops/panic the kernel."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T08:54:28.487Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/40dba7c26e897c637e91312b35f664f1d4d0073c"
        },
        {
          "url": "https://git.kernel.org/stable/c/ef7b10f3cac7810ddcfd976304fd125aca33d144"
        },
        {
          "url": "https://git.kernel.org/stable/c/5c1149e2abe0b7489300736b8277b45b113de67f"
        },
        {
          "url": "https://git.kernel.org/stable/c/0a2a464f863187f97e96ebc6384c052cafd4a54c"
        }
      ],
      "title": "crypto: hisilicon/sec - fix the aead software fallback for engine",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2022-49260",
    "datePublished": "2025-02-26T01:56:12.548Z",
    "dateReserved": "2025-02-26T01:49:39.296Z",
    "dateUpdated": "2026-08-05T08:54:28.487Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…