GHSA-29vw-w4vv-p6rrMediumCVSS 5.5

In the Linux kernel, the following vulnerability has been resolved: crypto: seqiv - Do not use...

Published
January 14, 2026
Last Modified
July 14, 2026

🔗 CVE IDs covered (1)

📋 Description

In the Linux kernel, the following vulnerability has been resolved:

crypto: seqiv - Do not use req->iv after crypto_aead_encrypt

As soon as crypto_aead_encrypt is called, the underlying request may be freed by an asynchronous completion. Thus dereferencing req->iv after it returns is invalid.

Instead of checking req->iv against info, create a new variable unaligned_info and use it for that purpose instead.

🔗 References (10)