Access Vulnerability in Linux Kernel's Cryptography Module
CVE-2026-80831
Currently unrated
What is CVE-2026-80831?
A vulnerability exists within the Linux Kernel's cryptographic module, specifically in the mxs_dcp_aes_block_crypt() function. This function improperly uses sg_dma_len() without first mapping the source scatterlist with dma_map_sg(). As a result, sg_dma_len() may yield zero or an outdated DMA length, which could potentially lead to encryption and decryption operations processing an incorrect quantity of bytes. This flaw highlights the need for careful handling of scatterlist lengths to ensure data integrity during cryptographic operations.
Affected Version(s)
Linux 15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5
Linux 15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5 < 04201dcc88b26eac52f736e39727fc5c420b7257
Linux 15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5