CVE-2026-43033High· 7.8▾ TwilightIn the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption When decrypting data that is not in-place (src != dst), there is no need to save the …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via CVEORG
Last analysed / modified upstream
0.1%
In the Linux kernel, the following vulnerability has been resolved:
crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption
When decrypting data that is not in-place (src != dst), there is no need to save the high-order sequence bits in dst as it could simply be re-copied from the source.
However, the data to be hashed need to be rearranged accordingly.
Thanks,
Linux >= 104880a6b470958ddc30e139c41aa4f6ed3a5234 < 8c62f618576519dbed6816fafc623ce592953025Linux >= 104880a6b470958ddc30e139c41aa4f6ed3a5234 < d589abd8b019b07075fda255ceab8c8e950cdb3fLinux >= 104880a6b470958ddc30e139c41aa4f6ed3a5234 < 5466e7d0cd9e4f9cef9d8f18f18b60e7bc1c77e5Linux >= 104880a6b470958ddc30e139c41aa4f6ed3a5234 < d0c4ff6812386880f30bc64c2921299cc4d7b47fLinux >= 104880a6b470958ddc30e139c41aa4f6ed3a5234 < 89fe118b6470119b20c04afc36e45b81a69ea11fLinux >= 104880a6b470958ddc30e139c41aa4f6ed3a5234 < 153d5520c3f9fd62e71c7e7f9e34b59cf411e555Linux >= 104880a6b470958ddc30e139c41aa4f6ed3a5234 < cded4002d22177e8deaca1f257ecd932c9582b6bLinux >= 104880a6b470958ddc30e139c41aa4f6ed3a5234 < e02494114ebf7c8b42777c6cd6982f113bfdbec7Linux 4.3Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-90055NoneIn the Linux kernel, the following vulnerability has been resolved: usb: atm: usbatm: fix invalid ci_range initialization syzbot reported a shift-out-of-bounds in __vcc_connect(): UBSAN: shift-out-of-bounds in net/atm/common.c:382:3…
CVE-2026-90060NoneIn the Linux kernel, the following vulnerability has been resolved: ALSA: control: Don't add invalid kcontrols to LED layer The kcontrol LED state layer tries to track the all associated kcontrol elements with naive assumptions that th…
CVE-2026-90168NoneRejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-90196NoneIn the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: validate topology volume range before allocation SOF treats the topology mixer min and max values as non-negative indices into its volume table
CVE-2026-90209NoneIn the Linux kernel, the following vulnerability has been resolved: s390/debug: Fix deadlock during unregister Unregistering an s390dbf debug area while one of the associated debugfs files is being written to can cause a deadlock: $ e…
CVE-2026-90221NoneIn the Linux kernel, the following vulnerability has been resolved: nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing nci_core_init_rsp_packet_v1() and nci_core_init_rsp_packet_v2() parse the CORE_INIT_RSP packet witho…