Executive brief
A technical issue was identified in the Linux kernel's Atmel Triple DES (TDES) cryptographic driver. On certain hardware platforms, the system might read outdated or 'stale' data from memory instead of the actual encrypted or decrypted results. This could lead to incorrect data processing or potential information leakage in specific local environments.
Technical details
A flaw was discovered in the Linux kernel's crypto: atmel-tdes driver where the DMA synchronization direction was incorrectly implemented. Specifically, the driver used dma_sync_single_for_device() instead of dma_sync_single_for_cpu() before the CPU consumed the DMA output. On non-coherent hardware platforms, this mismatch fails to properly invalidate the CPU cache, causing the CPU to read stale data rather than the results written by the DMA hardware. This issue affects both the Peripheral Data Controller (PDC) and standard DMA paths within the driver. Patches have been released across multiple stable kernel branches to correct the synchronization call.
Affected products
- Linux Linux kernel atmel-tdes driver
Timeline
- 2026-03-07: other: Initial patch authored
- 2026-03-15: patched: Patch committed to mainline kernel
- 2026-05-27: advisory: CVE published and NVD record created
References
- https://git.kernel.org/stable/c/12a0adfe498cd5d87e6365d7ca5f6b3eed79e523
- https://git.kernel.org/stable/c/5281e6e2302362f6b75b70cbfe4098d2a25dafd9
- https://git.kernel.org/stable/c/863d11b3927703ad95077c81a8a6489c5c7872f7
- https://git.kernel.org/stable/c/b5f5df801d161ba244f391519cbff2f4e5c6edc2
- https://git.kernel.org/stable/c/c8a9a647532f5c2a04180352693215e24e9dba03