CVE-2026-64312 (GCVE-0-2026-64312)
Vulnerability from cvelistv5
Published
2026-07-25 08:49
Modified
2026-08-17 04:53
Severity ?
VLAI Severity ?
EPSS score ?
Summary
In the Linux kernel, the following vulnerability has been resolved:
crypto: pcrypt - restore callback for non-parallel fallback
pcrypt installs pcrypt_aead_done() on the child AEAD request before
trying to submit it through padata. If padata_do_parallel() returns
-EBUSY, pcrypt falls back to calling the child AEAD directly.
That fallback must not keep the padata completion callback. Otherwise
an asynchronous completion runs pcrypt_aead_done() even though the
request was never enrolled in padata.
Restore the original request callback and callback data before calling
the child AEAD directly. This keeps the fallback path aligned with a
direct AEAD request while leaving the parallel path unchanged.
References
Impacted products
| Vendor | Product | Version | ||
|---|---|---|---|---|
| Linux | Linux |
Version: a92ccd3618e42333ac6f150ecdac14dca298bc7a Version: 96001f52ae8c70e2c736d3e1e5dc53d5b521e5ca Version: 92834692a539b5b7f409e467a14667d64713b732 Version: 5edae7a9a35606017ee6e05911c290acee9fee5a Version: 7ddab756f2de5b7b43c122ebebdf37f400fb2b6f Version: 662f2f13e66d3883b9238b0b96b17886179e60e2 Version: 662f2f13e66d3883b9238b0b96b17886179e60e2 Version: 662f2f13e66d3883b9238b0b96b17886179e60e2 Version: dd8bf8eb5beba1e7c3b11a9a5a58ccbf345a69e6 Version: fca8aed12218f96b38e374ff264d78ea1fbd23cc Version: a8e0074ffb38c9a5964a221bb998034d016c93a2 Version: 5.10.231 ≤ Version: 5.15.174 ≤ Version: 6.1.120 ≤ Version: 6.6.64 ≤ Version: 6.12.2 ≤ Version: 4.19.325 ≤ Version: 5.4.287 ≤ Version: 6.11.11 ≤ |
||
{
"containers": {
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "Linux",
"programFiles": [
"crypto/pcrypt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"lessThan": "81ce16d938db9b88cdc231522c0358395ae8c6b5",
"status": "affected",
"version": "a92ccd3618e42333ac6f150ecdac14dca298bc7a",
"versionType": "git"
},
{
"lessThan": "3920c5f6edc341729d20d0507e466c6d3b11f372",
"status": "affected",
"version": "96001f52ae8c70e2c736d3e1e5dc53d5b521e5ca",
"versionType": "git"
},
{
"lessThan": "ae93c5b3e2a2968b56d772ca1d06615927b7cc36",
"status": "affected",
"version": "92834692a539b5b7f409e467a14667d64713b732",
"versionType": "git"
},
{
"lessThan": "82789a44415e3e31168229421b138278dfb16412",
"status": "affected",
"version": "5edae7a9a35606017ee6e05911c290acee9fee5a",
"versionType": "git"
},
{
"lessThan": "4711ca06bd169a2cbc9cc59a6de2ed512c41a880",
"status": "affected",
"version": "7ddab756f2de5b7b43c122ebebdf37f400fb2b6f",
"versionType": "git"
},
{
"lessThan": "c4bd2f4c35b0e15b6040c2f7e7e7986780c066cf",
"status": "affected",
"version": "662f2f13e66d3883b9238b0b96b17886179e60e2",
"versionType": "git"
},
{
"lessThan": "83fa1397d5853de1e27dd52ec44b068ff358ca18",
"status": "affected",
"version": "662f2f13e66d3883b9238b0b96b17886179e60e2",
"versionType": "git"
},
{
"lessThan": "ed459fe319376e876de433d12b6c6772e612ca36",
"status": "affected",
"version": "662f2f13e66d3883b9238b0b96b17886179e60e2",
"versionType": "git"
},
{
"status": "affected",
"version": "dd8bf8eb5beba1e7c3b11a9a5a58ccbf345a69e6",
"versionType": "git"
},
{
"status": "affected",
"version": "fca8aed12218f96b38e374ff264d78ea1fbd23cc",
"versionType": "git"
},
{
"status": "affected",
"version": "a8e0074ffb38c9a5964a221bb998034d016c93a2",
"versionType": "git"
},
{
"lessThan": "5.10.261",
"status": "affected",
"version": "5.10.231",
"versionType": "semver"
},
{
"lessThan": "5.15.212",
"status": "affected",
"version": "5.15.174",
"versionType": "semver"
},
{
"lessThan": "6.1.178",
"status": "affected",
"version": "6.1.120",
"versionType": "semver"
},
{
"lessThan": "6.6.145",
"status": "affected",
"version": "6.6.64",
"versionType": "semver"
},
{
"lessThan": "6.12.96",
"status": "affected",
"version": "6.12.2",
"versionType": "semver"
},
{
"lessThan": "4.20",
"status": "affected",
"version": "4.19.325",
"versionType": "semver"
},
{
"lessThan": "5.5",
"status": "affected",
"version": "5.4.287",
"versionType": "semver"
},
{
"lessThan": "6.12",
"status": "affected",
"version": "6.11.11",
"versionType": "semver"
}
]
},
{
"defaultStatus": "affected",
"product": "Linux",
"programFiles": [
"crypto/pcrypt.c"
],
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"versions": [
{
"status": "affected",
"version": "6.13"
},
{
"lessThan": "6.13",
"status": "unaffected",
"version": "0",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.10.*",
"status": "unaffected",
"version": "5.10.261",
"versionType": "semver"
},
{
"lessThanOrEqual": "5.15.*",
"status": "unaffected",
"version": "5.15.212",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.1.*",
"status": "unaffected",
"version": "6.1.178",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.6.*",
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.12.*",
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver"
},
{
"lessThanOrEqual": "6.18.*",
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver"
},
{
"lessThanOrEqual": "7.1.*",
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver"
},
{
"lessThanOrEqual": "*",
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.10.261",
"versionStartIncluding": "5.10.231",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "5.15.212",
"versionStartIncluding": "5.15.174",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.1.178",
"versionStartIncluding": "6.1.120",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "6.6.64",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.12.2",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionEndExcluding": "7.2",
"versionStartIncluding": "6.13",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "4.19.325",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.4.287",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"versionStartIncluding": "6.11.11",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: pcrypt - restore callback for non-parallel fallback\n\npcrypt installs pcrypt_aead_done() on the child AEAD request before\ntrying to submit it through padata. If padata_do_parallel() returns\n-EBUSY, pcrypt falls back to calling the child AEAD directly.\n\nThat fallback must not keep the padata completion callback. Otherwise\nan asynchronous completion runs pcrypt_aead_done() even though the\nrequest was never enrolled in padata.\n\nRestore the original request callback and callback data before calling\nthe child AEAD directly. This keeps the fallback path aligned with a\ndirect AEAD request while leaving the parallel path unchanged."
}
],
"metrics": [
{
"cvssV3_1": {
"baseScore": 7.5,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"version": "3.1"
},
"scenarios": [
{
"lang": "en",
"value": "AV:N - pcrypt is designed for network-facing IPsec use, and an inbound ESP packet can traverse xfrm_input(), esp_input(), crypto_aead_decrypt(), and pcrypt_aead_decrypt().\nAC:L - In load-responsive CPU-hotplug deployments, an attacker can flood qualifying ESP requests across repeated PADATA_RESET windows without precise timing or an uncontrollable memory-layout condition.\nPR:N - The ESP SPI is transmitted in clear, and the faulty path is reached before the child AEAD validates the integrity tag, so an unauthenticated on-path attacker needs no target-system privileges.\nUI:N - Packet delivery and asynchronous completion require no victim action.\nS:U - The failure affects the same kernel security authority processing the request and does not cross a VM, IOMMU, or sandbox boundary.\nC:N - The rejected request retains a zero padata-\u003epd pointer, producing a NULL dereference without an out-of-bounds read or information disclosure.\nI:N - The callback writes only the completion status into its valid request context before dereferencing NULL; it provides no attacker-directed corruption or write primitive.\nA:H - padata_do_serial() dereferences the uninitialized padata-\u003epd pointer, causing a kernel oops or panic that can terminate the system and can be retriggered."
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T04:53:12.187Z",
"orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"shortName": "Linux"
},
"references": [
{
"url": "https://git.kernel.org/stable/c/81ce16d938db9b88cdc231522c0358395ae8c6b5"
},
{
"url": "https://git.kernel.org/stable/c/3920c5f6edc341729d20d0507e466c6d3b11f372"
},
{
"url": "https://git.kernel.org/stable/c/ae93c5b3e2a2968b56d772ca1d06615927b7cc36"
},
{
"url": "https://git.kernel.org/stable/c/82789a44415e3e31168229421b138278dfb16412"
},
{
"url": "https://git.kernel.org/stable/c/4711ca06bd169a2cbc9cc59a6de2ed512c41a880"
},
{
"url": "https://git.kernel.org/stable/c/c4bd2f4c35b0e15b6040c2f7e7e7986780c066cf"
},
{
"url": "https://git.kernel.org/stable/c/83fa1397d5853de1e27dd52ec44b068ff358ca18"
},
{
"url": "https://git.kernel.org/stable/c/ed459fe319376e876de433d12b6c6772e612ca36"
}
],
"title": "crypto: pcrypt - restore callback for non-parallel fallback",
"x_generator": {
"engine": "bippy-1.2.0"
}
}
},
"cveMetadata": {
"assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"assignerShortName": "Linux",
"cveId": "CVE-2026-64312",
"datePublished": "2026-07-25T08:49:43.940Z",
"dateReserved": "2026-07-19T15:36:31.779Z",
"dateUpdated": "2026-08-17T04:53:12.187Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Loading…
Loading…
Sightings
| Author | Source | Type | Date |
|---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Published Proof of Concept: A public proof of concept is available for this vulnerability.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…