Executive brief
The Linux kernel's ecryptfs encryption layer contains a buffer overflow vulnerability in how it processes encrypted passphrase packets. An attacker with the ability to supply a specially crafted encrypted key file can trigger out-of-bounds memory writes, potentially leading to privilege escalation, data corruption, or system crashes.
Technical details
The vulnerability exists in parse_tag_3_packet() and decrypt_passphrase_encrypted_session_key() functions, which process ecryptfs Tag 3 packets without properly validating the encrypted_key_size field against ECRYPTFS_MAX_KEY_BYTES (64 bytes). When encrypted_key_size exceeds 64 bytes, two out-of-bounds writes occur: (1) crypto_skcipher_decrypt() writes beyond the 64-byte decrypted_key buffer into the parent ecryptfs_auth_tok struct, and (2) memcpy() subsequently writes into crypt_stat->key[64], corrupting critical kernel data structures (root_iv, keysig_list, mutexes). The vulnerability is exploitable only with AES-192 cipher (code 0x08), which allows the kernel to accept oversized keys. A fix has been implemented that bounds encrypted_key_size against ECRYPTFS_MAX_KEY_BYTES, mirroring the existing validation in the PKI decryption path.
Affected products
- Linux Linux kernel multiple versions prior to fix
Timeline
- 2026-09-11: disclosed
- 2026-09-11: patched: Fix applied: validate encrypted_key_size against ECRYPTFS_MAX_KEY_BYTES in parse_tag_3_packet()