Executive brief
A vulnerability in the Linux kernel's cryptographic library for ARM processors could lead to system instability or data errors. The issue occurs when the system performs specific encryption tasks (Poly1305) in a way that accidentally overwrites data in the processor's registers. This can result in incorrect security calculations or cause other running programs to behave unpredictably or crash.
Technical details
A regression was introduced in the Linux kernel's ARM Poly1305 implementation where a necessary SIMD usability check was removed. When Poly1305 functions are invoked in contexts where SIMD registers are marked as unusable, the code fails to fall back to non-SIMD paths, leading to the corruption of registers belonging to other tasks or the generation of incorrect MACs. The fix restores the safety check using 'may_use_simd()' to ensure SIMD instructions are only executed when the architectural state is safely preserved. This affects ARM-based systems running kernel versions between 6.16 and 6.16.4.
Affected products
- Linux Linux Kernel 6.16 to 6.16.4
Timeline
- 2025-07-06: patched: Initial patch authored by Eric Biggers
- 2025-09-15: disclosed: CVE published