{"id":"CVE-2026-80836","title":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: virtio - bound the akcipher result length\n\nvirtio_crypto_dataq_akcipher_callback() sets the result length from the\ndevice-reported response length without bound…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: virtio - bound the akcipher result length\n\nvirtio_crypto_dataq_akcipher_callback() sets the result length from the\ndevice-reported response length without bound…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= a36bd0ad9fbf69d0d711b1c105954ce8d6cc144a < 12c4f29e97f31b013f77ad65ba7daeb02aaa6abe","Linux >= a36bd0ad9fbf69d0d711b1c105954ce8d6cc144a < 5545de5050cbc3594506d74f2c392b0716cf8bca","Linux >= a36bd0ad9fbf69d0d711b1c105954ce8d6cc144a < 3fda114a42f1510a4ec8a0b17a0cfc997952ccc2","Linux >= a36bd0ad9fbf69d0d711b1c105954ce8d6cc144a < 1f9f877b1ef1fbd4ee95571cddf39c8002cee252","Linux >= a36bd0ad9fbf69d0d711b1c105954ce8d6cc144a < f77a956f6a19f9463ef1527c9d0cda50dded6b92","Linux 5.19"],"published":"2026-09-04","updated":"2026-09-21","sourceUpdated":"2026-09-21T14:17:20.680","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80836","references":[{"url":"https://git.kernel.org/stable/c/12c4f29e97f31b013f77ad65ba7daeb02aaa6abe","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/1f9f877b1ef1fbd4ee95571cddf39c8002cee252","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3fda114a42f1510a4ec8a0b17a0cfc997952ccc2","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5545de5050cbc3594506d74f2c392b0716cf8bca","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/f77a956f6a19f9463ef1527c9d0cda50dded6b92","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"epss":0.00168,"epssPercentile":0.06487,"ingestedAt":"2026-09-21T13:37:22.836Z","slug":"CVE-2026-80836","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: virtio - bound the akcipher result length\n\nvirtio_crypto_dataq_akcipher_callback() sets the result length from the\ndevice-reported response length without bounding it to the destination\nbuffer, which was allocated for the original request length.\nsg_copy_from_buffer() then reads that many bytes from the destination\nbuffer; a backend reporting a larger length over-reads adjacent kernel\nheap into the caller's scatterlist (an out-of-bounds read).\n\nClamp the reported length to the originally requested destination length.\nA conforming device reports no more than that, so valid results are\nunaffected.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}