Out-of-bounds read in Linux kernel - CVE-2026-80836
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in virtio_crypto_dataq_akcipher_callback() when handling a device-reported akcipher response length. A local user can cause a virtio crypto backend to report an oversized result length to disclose sensitive information.