Executive brief
A vulnerability exists in the cryptodev-linux driver, a component used to allow applications to access hardware-accelerated encryption. A local attacker can exploit a flaw in how the driver manages memory pages to gain full administrative (root) control over the Linux system. This could allow an unauthorized user to bypass security restrictions, access sensitive data, or modify system files like the password database.
Technical details
A use-after-free (UAF) vulnerability exists in the get_userbuf function within the /dev/crypto device driver of cryptodev-linux. The flaw stems from improper page reference counting; specifically, an attacker can trigger a code path where release_user_pages is called to decrement reference counts on pages that were never properly acquired or were already released. By repeatedly invoking the CIOCCRYPT ioctl with specifically crafted source and destination buffers (e.g., setting src to NULL and dst to an invalid address), a local attacker can decrement a page's reference count to zero, causing the kernel to free a page that is still in use. This allows for page-level UAF exploitation, which can be leveraged via techniques like struct file spraying to achieve local privilege escalation (LPE). A patch is available in the project's GitHub repository.
Affected products
- cryptodev-linux cryptodev-linux 1.14 and prior
Timeline
- 2025-12-06: patched: Pull request #104 submitted to fix the UAF
- 2026-01-12: other: Detailed exploitation write-up published by researcher
- 2026-03-25: advisory: CVE-2026-28529 published