Junglewise Threat Intelligence

CVE-2026-43330: Linux Kernel CAAM crypto driver out-of-bounds write in ahash_setkey

CVE-2026-43330 · Severity: high · CVSS 7.8 · Published 2026-05-08

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's cryptographic driver for CAAM hardware could allow a local attacker to cause a system crash or potentially gain unauthorized access to data. The issue occurs when the system processes specific security keys that are longer than expected, leading to memory corruption. This affects systems using NXP CAAM (Cryptographic Acceleration and Assurance Module) hardware acceleration.

Technical details

An out-of-bounds read and potential memory corruption exists in the Linux kernel's CAAM driver (drivers/crypto/caam/caamalg_qi2.c). When an HMAC key exceeds the block size, the `ahash_setkey` function incorrectly used `kmemdup` with an `aligned_len` parameter that exceeded the actual `keylen` of the source buffer. This resulted in an out-of-bounds read from the source key buffer. Furthermore, improper rounding for DMA cache alignment could lead to the hashed key corrupting neighboring memory. The fix replaces `kmemdup` with `kmalloc` followed by a size-constrained `memcpy`. This is a local vulnerability requiring low privileges.

Affected products

  • Linux Linux Kernel 6.3 to 6.6.134, 6.7 to 6.12.81, 6.13 to 6.18.22, 6.19 to 6.19.12, 7.0-rc1 to 7.0-rc6

Timeline

  • 2026-03-17: other: Patch authored
  • 2026-05-08: disclosed: CVE published
  • 2026-05-08: advisory
  • 2026-05-18: other: NVD analysis completed

References

Related threats