Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43078

Опубликовано: 06 мая 2026
Источник: redhat
CVSS3: 7.3

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl When page reassignment was added to af_alg_pull_tsgl the original loop wasn't updated so it may try to reassign one more page than necessary. Add the check to the reassignment so that this does not happen. Also update the comment which still refers to the obsolete offset argument.

A flaw was found in the Linux kernel. Specifically, within the crypto: af_alg component, a page reassignment overflow could occur in the af_alg_pull_tsgl function. This vulnerability arises because the original loop was not updated, potentially allowing it to reassign one more page than necessary. This could lead to unexpected system behavior or a denial of service (DoS).

Отчет

af_alg_pull_tsgl can reassign one extra page into the destination scatterlist because the reassignment path did not check whether plen is non zero. A local process using AF_ALG crypto sockets can craft buffer and scatterlist state so the function advances the destination index for a zero length fragment, which can overrun the caller allocated dst SG entries. For the CVSS the PR:L is used because triggering requires local code execution through the AF_ALG socket API, but not administrator privileges in typical configurations. The issue is not network reachable because the vulnerable input is a local crypto socket operation. Impact is at least local denial of service via kernel crash. In the paranoid case, the destination scatterlist overwrite is treated as a plausible memory corruption primitive with possible confidentiality and integrity impact.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelAffected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelWill not fix
Red Hat Enterprise Linux 8kernel-rtAffected
Red Hat Enterprise Linux 9kernelAffected
Red Hat Enterprise Linux 9kernel-rtAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-193
https://bugzilla.redhat.com/show_bug.cgi?id=2467023kernel: crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl When page reassignment was added to af_alg_pull_tsgl the original loop wasn't updated so it may try to reassign one more page than necessary. Add the check to the reassignment so that this does not happen. Also update the comment which still refers to the obsolete offset argument.

CVSS3: 7.8
nvd
3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl When page reassignment was added to af_alg_pull_tsgl the original loop wasn't updated so it may try to reassign one more page than necessary. Add the check to the reassignment so that this does not happen. Also update the comment which still refers to the obsolete offset argument.

CVSS3: 7.8
debian
3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: c ...

CVSS3: 7.8
github
3 месяца назад

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Fix page reassignment overflow in af_alg_pull_tsgl When page reassignment was added to af_alg_pull_tsgl the original loop wasn't updated so it may try to reassign one more page than necessary. Add the check to the reassignment so that this does not happen. Also update the comment which still refers to the obsolete offset argument.

oracle-oval
3 месяца назад

ELSA-2026-50262: Unbreakable Enterprise kernel security update (IMPORTANT)

7.3 High

CVSS3