Executive brief
A vulnerability in the Linux kernel's HiSilicon SEC2 crypto driver could cause a system crash or unpredictable behavior under heavy load. The issue occurs when the hardware finishes processing a data packet and clears its memory before the software is finished with it. This could lead to a service outage or system instability in environments using HiSilicon hardware acceleration.
Technical details
A use-after-free (UAF) vulnerability exists in drivers/crypto/hisilicon/sec2/sec_crypto.c within the Linux kernel. The root cause is a race condition where, under heavy load, hardware may complete packet processing and free the associated request structure (req) before the qp_send_message function finishes execution. If the software subsequently attempts to increment debug counters using the freed request pointer, a UAF occurs. The fix involves referencing the qp_ctx structure, which remains valid throughout the transmission process, instead of the transient request structure. This issue affects systems using HiSilicon SEC2 hardware accelerators and has been patched in various stable kernel branches.
Affected products
- Linux Linux Kernel 6.17 to 6.18.33, 7.0 to 7.0.10
Timeline
- 2026-03-21: other: Patch authored
- 2026-06-24: disclosed: CVE published