Executive brief
A vulnerability in the Linux kernel's cryptographic services could allow a local user to crash the system. The issue occurs when the kernel processes certain encryption requests from applications, leading to a system instability or a complete halt (denial of service). This could disrupt business operations and affect the availability of services running on the impacted Linux systems.
Technical details
A vulnerability exists in the Linux kernel's AF_ALG (crypto) socket interface due to the use of an uninitialized resource (CWE-908). Specifically, in the `af_alg_sendmsg` function, if an error occurs that causes the function to abort, the `ctx->merge` variable may retain a 'garbage' value from a previous loop iteration. A subsequent call to `af_alg_sendmsg` may then attempt to perform a merge operation based on this invalid value, resulting in a kernel crash. This is a local attack vector requiring low privileges and no user interaction. The issue has been resolved by ensuring `ctx->merge` is explicitly set to zero at the beginning of the message processing loop.
Affected products
- Linux Linux Kernel 2.6.38 to 6.16.9
Timeline
- 2025-09-16: patched: Initial patch authored by Herbert Xu
- 2025-10-04: advisory: CVE published by NVD
References
- https://git.kernel.org/stable/c/045ee26aa3920a47ec46d7fcb302420bf01fd753
- https://git.kernel.org/stable/c/2374c11189ef704a3e4863646369f1b8e6a27d71
- https://git.kernel.org/stable/c/24c1106504c625fabd3b7229611af617b4c27ac7
- https://git.kernel.org/stable/c/28f6f37abca7c5c9eb3959c66310f1d4d98b8aaf
- https://git.kernel.org/stable/c/6241b9e2809b12da9130894cf5beddf088dc1b8a
- https://git.kernel.org/stable/c/9574b2330dbd2b5459b74d3b5e9619d39299fc6f
- https://git.kernel.org/stable/c/db2b42425dfbde4983b0c20fb7cfa05f70e6a745