SB20260905114 - Incorrect calculation in Linux kernel crypto driver
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Incorrect calculation (CVE-ID: CVE-2026-80831)
CWE-ID: CWE-682 - Incorrect Calculation
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause encryption and decryption operations to process an incorrect number of bytes.
The vulnerability exists due to improper use of an unmapped DMA scatterlist length in mxs_dcp_aes_block_crypt() when processing source scatterlists. A local user can trigger processing of affected source scatterlists to cause encryption and decryption operations to process an incorrect number of bytes.
The issue occurs when CONFIG_NEED_SG_DMA_LENGTH is enabled.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/04201dcc88b26eac52f736e39727fc5c420b7257
- https://git.kernel.org/stable/c/0e9edb108a63bbbef952dfcbc597e34ed9c1fb74
- https://git.kernel.org/stable/c/1537bd55b4f842565068c54b47cd2ae1777d5f8f
- https://git.kernel.org/stable/c/182f16a20d329a1c818d51dad57d9bf43d356c7c
- https://git.kernel.org/stable/c/6ef9a4afb52cb102ab038cd42352c142d8505d09
- https://git.kernel.org/stable/c/c5bcb084a9871e5b62afb5f48b60adfa13b5d9f8
- https://git.kernel.org/stable/c/da14fae5203b72ca71ccfa9af8de9249e40d533a
- https://git.kernel.org/stable/c/e72a795df521cb65b7c4705cc11078cdacfaa2f4
- https://git.kernel.org/stable/c/fd0f211b27a6ec2ebd8c315683401b43adcc5511