CVE-2026-23222 (GCVE-0-2026-23222)
Vulnerability from cvelistv5
Published
2026-02-18 14:53
Modified
2026-08-05 12:20
Summary
In the Linux kernel, the following vulnerability has been resolved: crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly The existing allocation of scatterlists in omap_crypto_copy_sg_lists() was allocating an array of scatterlist pointers, not scatterlist objects, resulting in a 4x too small allocation. Use sizeof(*new_sg) to get the correct object size.
Impacted products
Vendor Product Version
Linux Linux Version: 74ed87e7e7f7197137164738dd0610ccd5ec5ed1
Version: 74ed87e7e7f7197137164738dd0610ccd5ec5ed1
Version: 74ed87e7e7f7197137164738dd0610ccd5ec5ed1
Version: 74ed87e7e7f7197137164738dd0610ccd5ec5ed1
Version: 74ed87e7e7f7197137164738dd0610ccd5ec5ed1
Version: 74ed87e7e7f7197137164738dd0610ccd5ec5ed1
Version: 74ed87e7e7f7197137164738dd0610ccd5ec5ed1
Version: 74ed87e7e7f7197137164738dd0610ccd5ec5ed1
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "affected": [
          {
            "defaultStatus": "unknown",
            "product": "RUGGEDCOM RST2428P",
            "vendor": "Siemens",
            "versions": [
              {
                "lessThan": "V4.0",
                "status": "affected",
                "version": "0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-06-02T13:01:02.214Z",
          "orgId": "0b142b55-0307-4c5a-b3c9-f314f3fb7c5e",
          "shortName": "siemens-SADP"
        },
        "references": [
          {
            "url": "https://cert-portal.siemens.com/productcert/html/ssa-253495.html"
          }
        ],
        "x_adpType": "supplier"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "drivers/crypto/omap-crypto.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "953c81941b0ad373674656b8767c00234ebf17ac",
              "status": "affected",
              "version": "74ed87e7e7f7197137164738dd0610ccd5ec5ed1",
              "versionType": "git"
            },
            {
              "lessThan": "31aff96a41ae6f1f1687c065607875a27c364da8",
              "status": "affected",
              "version": "74ed87e7e7f7197137164738dd0610ccd5ec5ed1",
              "versionType": "git"
            },
            {
              "lessThan": "79f95b51d4278044013672c27519ae88d07013d8",
              "status": "affected",
              "version": "74ed87e7e7f7197137164738dd0610ccd5ec5ed1",
              "versionType": "git"
            },
            {
              "lessThan": "6edf8df4bd29f7bfd245b67b2c31d905f1cfc14b",
              "status": "affected",
              "version": "74ed87e7e7f7197137164738dd0610ccd5ec5ed1",
              "versionType": "git"
            },
            {
              "lessThan": "c184341920ed78b6466360ed7b45b8922586c38f",
              "status": "affected",
              "version": "74ed87e7e7f7197137164738dd0610ccd5ec5ed1",
              "versionType": "git"
            },
            {
              "lessThan": "2ed27b5a1174351148c3adbfc0cd86d54072ba2e",
              "status": "affected",
              "version": "74ed87e7e7f7197137164738dd0610ccd5ec5ed1",
              "versionType": "git"
            },
            {
              "lessThan": "d1836c628cb72734eb5f7dfd4c996a9c18bba3ad",
              "status": "affected",
              "version": "74ed87e7e7f7197137164738dd0610ccd5ec5ed1",
              "versionType": "git"
            },
            {
              "lessThan": "1562b1fb7e17c1b3addb15e125c718b2be7f5512",
              "status": "affected",
              "version": "74ed87e7e7f7197137164738dd0610ccd5ec5ed1",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "drivers/crypto/omap-crypto.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.13"
            },
            {
              "lessThan": "4.13",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.251",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.201",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.164",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.125",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.72",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.11",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.19.*",
              "status": "unaffected",
              "version": "6.19.1",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.0",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.251",
                  "versionStartIncluding": "4.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.201",
                  "versionStartIncluding": "4.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.164",
                  "versionStartIncluding": "4.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.125",
                  "versionStartIncluding": "4.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.72",
                  "versionStartIncluding": "4.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.11",
                  "versionStartIncluding": "4.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.19.1",
                  "versionStartIncluding": "4.13",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.0",
                  "versionStartIncluding": "4.13",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly\n\nThe existing allocation of scatterlists in omap_crypto_copy_sg_lists()\nwas allocating an array of scatterlist pointers, not scatterlist objects,\nresulting in a 4x too small allocation.\n\nUse sizeof(*new_sg) to get the correct object size."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The OMAP crypto driver is accessed through the kernel crypto API, reachable by local users via AF_ALG sockets or kernel-internal crypto consumers. No network-facing path directly triggers this driver; physical device access to an OMAP ARM SoC system is not required beyond local login.\nAC:L - A local attacker controls the crypto request input (data size and scatterlist geometry) via AF_ALG, and can craft requests that trigger the BAD_DATA_LENGTH path in omap_crypto_check_sg where scatterlist entry lengths don\u0027t match the total, reliably reaching the vulnerable allocation.\nPR:L - AF_ALG sockets are accessible to any unprivileged local user without special capabilities, allowing an ordinary user account to submit crypto requests to the OMAP hardware crypto driver.\nUI:N - No user interaction is needed; the attacker directly submits a crafted crypto request through the AF_ALG socket interface.\nS:U - The vulnerability is in the kernel and impacts the kernel itself; there is no crossing of a security boundary such as a VM or sandbox escape.\nC:H - The heap buffer overflow writes attacker-influenced scatterlist data (page pointers, offsets, lengths from the attacker\u0027s scatterlist) past the allocated buffer into adjacent heap objects, which with heap grooming can be leveraged to read arbitrary kernel memory.\nI:H - The heap overflow corrupts adjacent kernel heap objects with attacker-influenced data; through heap spraying and grooming, this can overwrite function pointers or other security-sensitive structures, enabling arbitrary code execution.\nA:H - Writing beyond the allocated buffer corrupts adjacent heap metadata and objects, causing kernel crashes (oops/panic) when the corrupted data is subsequently accessed."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T12:20:41.276Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/953c81941b0ad373674656b8767c00234ebf17ac"
        },
        {
          "url": "https://git.kernel.org/stable/c/31aff96a41ae6f1f1687c065607875a27c364da8"
        },
        {
          "url": "https://git.kernel.org/stable/c/79f95b51d4278044013672c27519ae88d07013d8"
        },
        {
          "url": "https://git.kernel.org/stable/c/6edf8df4bd29f7bfd245b67b2c31d905f1cfc14b"
        },
        {
          "url": "https://git.kernel.org/stable/c/c184341920ed78b6466360ed7b45b8922586c38f"
        },
        {
          "url": "https://git.kernel.org/stable/c/2ed27b5a1174351148c3adbfc0cd86d54072ba2e"
        },
        {
          "url": "https://git.kernel.org/stable/c/d1836c628cb72734eb5f7dfd4c996a9c18bba3ad"
        },
        {
          "url": "https://git.kernel.org/stable/c/1562b1fb7e17c1b3addb15e125c718b2be7f5512"
        }
      ],
      "title": "crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-23222",
    "datePublished": "2026-02-18T14:53:25.504Z",
    "dateReserved": "2026-01-13T15:37:45.987Z",
    "dateUpdated": "2026-08-05T12:20:41.276Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…