Junglewise Threat Intelligence

CVE-2025-68726: Linux Kernel memory corruption in crypto AEAD reqsize handling

CVE-2025-68726 · Severity: critical · CVSS 9.8 · Published 2025-12-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's cryptographic subsystem can lead to system crashes or memory corruption. The affected component is responsible for Authenticated Encryption with Associated Data (AEAD), which is a standard method for ensuring both the confidentiality and integrity of data. An exploit could allow an attacker to disrupt operations or potentially access sensitive information by triggering improper memory handling during cryptographic operations.

Technical details

A vulnerability exists in the Linux kernel crypto API due to improper handling of the 'cra_reqsize' field within the AEAD (Authenticated Encryption with Associated Data) framework. While 'cra_reqsize' was introduced to unify request size handling across cryptographic types, the AEAD initialization function (crypto_aead_init_tfm) was not updated to correctly set the request size from this field. This oversight leads to memory corruption and kernel crashes when AEAD algorithms utilize the newer 'cra_reqsize' field instead of the legacy 'crypto_*_set_reqsize()' method. The fix involves adding explicit 'crypto_aead_set_reqsize' calls during TFM initialization. Patches are available in stable kernel branches 6.17.13, 6.18.2, and 6.19.

Affected products

  • Linux Linux Kernel 6.16 to 6.17.12, 6.18.1

Timeline

  • 2025-12-24: disclosed: Initial publication of the vulnerability advisory.
  • 2025-12-24: advisory
  • 2025-12-18: patched: Fixes committed to stable kernel trees.

References

Related threats