CVE-2026-80836
In the Linux kernel, the following vulnerability has been resolved:
crypto: virtio - bound the akcipher result length
virtio_crypto_dataq_akcipher_callback() sets the result length from the device-reported response length without bounding it to the destination buffer, which was allocated for the original request length. sg_copy_from_buffer() then reads that many bytes from the destination buffer; a backend reporting a larger length over-reads adjacent kernel heap into the caller's scatterlist (an out-of-bounds read).
Clamp the reported length to the originally requested destination length. A conforming device reports no more than that, so valid results are unaffected.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.17%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/12c4f29e97f31b013f77ad65ba7daeb02aaa6abe
- https://git.kernel.org/stable/c/1f9f877b1ef1fbd4ee95571cddf39c8002cee252
- https://git.kernel.org/stable/c/3fda114a42f1510a4ec8a0b17a0cfc997952ccc2
- https://git.kernel.org/stable/c/5545de5050cbc3594506d74f2c392b0716cf8bca
- https://git.kernel.org/stable/c/bd33cb19bcb432a4dd5e8f50be5e2547af1e9f78
- https://git.kernel.org/stable/c/f77a956f6a19f9463ef1527c9d0cda50dded6b92
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80836",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "a36bd0ad9fbf69d0d711b1c105954ce8d6cc144a",
"lessThan": "bd33cb19bcb432a4dd5e8f50be5e2547af1e9f78",
"versionType": "git"
},
{
"status": "affected",
"version": "a36bd0ad9fbf69d0d711b1c105954ce8d6cc144a",
"lessThan": "12c4f29e97f31b013f77ad65ba7daeb02aaa6abe",
"versionType": "git"
},
{
"status": "affected",
"version": "a36bd0ad9fbf69d0d711b1c105954ce8d6cc144a",
"lessThan": "5545de5050cbc3594506d74f2c392b0716cf8bca",
"versionType": "git"
},
{
"status": "affected",
"version": "a36bd0ad9fbf69d0d711b1c105954ce8d6cc144a",
"lessThan": "3fda114a42f1510a4ec8a0b17a0cfc997952ccc2",
"versionType": "git"
},
{
"status": "affected",
"version": "a36bd0ad9fbf69d0d711b1c105954ce8d6cc144a",
"lessThan": "1f9f877b1ef1fbd4ee95571cddf39c8002cee252",
"versionType": "git"
},
{
"status": "affected",
"version": "a36bd0ad9fbf69d0d711b1c105954ce8d6cc144a",
"lessThan": "f77a956f6a19f9463ef1527c9d0cda50dded6b92",
"versionType": "git"
}
],
"programFiles": [
"drivers/crypto/virtio/virtio_crypto_akcipher_algs.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.19"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.19",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.158",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.111",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.49",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.13",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2.3",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/crypto/virtio/virtio_crypto_akcipher_algs.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-04T16:18:11.913",
"references": [
{
"url": "https://git.kernel.org/stable/c/12c4f29e97f31b013f77ad65ba7daeb02aaa6abe",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/1f9f877b1ef1fbd4ee95571cddf39c8002cee252",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/3fda114a42f1510a4ec8a0b17a0cfc997952ccc2",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/5545de5050cbc3594506d74f2c392b0716cf8bca",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bd33cb19bcb432a4dd5e8f50be5e2547af1e9f78",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f77a956f6a19f9463ef1527c9d0cda50dded6b92",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: virtio - bound the akcipher result length\n\nvirtio_crypto_dataq_akcipher_callback() sets the result length from the\ndevice-reported response length without bounding it to the destination\nbuffer, which was allocated for the original request length.\nsg_copy_from_buffer() then reads that many bytes from the destination\nbuffer; a backend reporting a larger length over-reads adjacent kernel\nheap into the caller's scatterlist (an out-of-bounds read).\n\nClamp the reported length to the originally requested destination length.\nA conforming device reports no more than that, so valid results are\nunaffected."
}
],
"lastModified": "2026-10-03T11:17:40.163",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}