Junglewise Threat Intelligence

CVE-2026-45959: Linux Kernel CCP crash due to incorrect kfree cleanup usage

CVE-2026-45959 · Severity: info · Published 2026-05-27

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Crypto Coprocessor (CCP) driver can cause a system crash. The issue occurs during cryptographic operations when the system incorrectly attempts to free memory from the stack rather than the intended heap location. This results in a kernel panic, leading to a denial of service for the affected system.

Technical details

A vulnerability in the Linux kernel's crypto/ccp driver arises from the incorrect use of the `__cleanup(kfree)` attribute on a local pointer variable in `ccp_run_aes_gcm_cmd`. When a variable is annotated with `__cleanup(kfree)`, the compiler passes the address of the pointer itself (a stack address) to `kfree` upon scope exit, rather than the memory address stored within the pointer (the heap address returned by `kzalloc`). This results in an invalid deallocation of a stack address, causing a kernel crash. The issue was masked during compilation because `kfree` accepts a `void *`, which is compatible with the pointer-to-pointer type generated by the incorrect attribute. The fix replaces `__cleanup(kfree)` with the correct `__free(kfree)` macro.

Affected products

  • Linux Linux Kernel Fixed in 90f9090e3e74, 9a3ace9b010f, d5abcc33ee76

Timeline

  • 2026-01-09: other: Patch authored
  • 2026-05-27: advisory: NVD publication date

References