Executive brief
The Linux kernel's Keem Bay AES crypto driver had a timing bug where an interrupt handler could run before its supporting completion structure was initialized. An attacker with the ability to trigger IRQs on the device could cause a kernel crash or undefined behavior, affecting system stability and potentially enabling further exploitation.
Technical details
A race condition exists in kmb_ocs_aes_probe() where the device IRQ is registered before the irq_completion kernel structure is initialized. Once the IRQ handler (ocs_aes_irq_handler()) is registered, it can fire immediately and unconditionally calls complete() on the uninitialized completion object, leading to memory corruption or a kernel panic. The fix reorders initialization to call init_completion() before requesting the IRQ. The vulnerability is local to systems with Keem Bay OCS AES hardware and requires the ability to generate device interrupts.
Affected products
- Linux Linux kernel All versions with keembay AES driver prior to patch commit fce20289dd622cc7ab78d72c8a979a9f8b7cb10e
Timeline
- 2026-09-17: disclosed
- 2026-09-14: patched: Stable kernel patches committed; upstream fix commit fce20289dd622cc7ab78d72c8a979a9f8b7cb10e