Linux Kernel Vulnerability in Crypto QCE Registration Process
CVE-2026-80565
What is CVE-2026-80565?
A vulnerability in the Linux kernel's crypto QCE module allows for potential mishandling of algorithm registration failures. Specifically, when the ops->register_algs() function encounters an error, the error handling mechanism may incorrectly attempt to unregister algorithms in a loop without properly indexing them. This flawed error path could lead to unexpected behaviors or resource leaks, impacting the stability and security of systems relying on these algorithms. Correcting this issue ensures that previously registered algorithms are accurately unregistered, maintaining system integrity.
Affected Version(s)
Linux 9e403fea74ecbe6b4a4321f13bd4bc929382908d
Linux f52f00efd8c0088992ac07ef46af6096e4f0e52e
Linux 5d5b673b4dd260226b2202f66a920566c27051f3 < 1ece8e16c085e8cd60ecbdb641269aaa53d31da4