Out-of-bounds read in Linux kernel - CVE-2026-80832
Published: September 5, 2026
Vulnerability identifier: #VU147084
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80832
CWE-ID: CWE-125
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to cause incorrect CCM authentication tags.
The vulnerability exists due to buffer underallocation in qce_aead_ccm_prepare_buf_assoclen() when preparing CCM associated data. A local user can submit a CCM request with associated data to cause incorrect CCM authentication tags.
Affected software
Linux kernel
How to mitigate CVE-2026-80832
Install security update from vendor's repository.
External References
- https://git.kernel.org/stable/c/002f1f99aef7ea631cb687fc17bce64e4963f6aa
- https://git.kernel.org/stable/c/11775b35ce9f27e73d62188d7d38aa0dc0a219aa
- https://git.kernel.org/stable/c/2f65718b9c1095eef1ae9b374aa0384b1b083f3c
- https://git.kernel.org/stable/c/46a84efe2dbaddde89073a3c00c694486937c34b
- https://git.kernel.org/stable/c/4839f4c21f9c577eedef2919ced878a3057c7fc3
- https://git.kernel.org/stable/c/7f2345f47dd189625f657cd72437179ab4170ee1
- https://git.kernel.org/stable/c/c9e0f06a023107694698a7930616aeb460d91816
- https://git.kernel.org/stable/c/cc56d2b0d77cfeea061e98114992ee687d5eb4dd