---
id: CVE-2026-52972
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  crypto: af_alg - Cap AEAD AD length to 0x80000000

  In order to prevent arithmetic overflows when checking the TX
  buffer size, cap the associated data length to 0x80000000.
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  crypto: af_alg - Cap AEAD AD length to 0x80000000

  In order to prevent arithmetic overflows when checking the TX
  buffer size, cap the associated data length to 0x80000000.
severity: none
published: '2026-06-24'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-52972'
references:
  - url: 'https://git.kernel.org/stable/c/265ac26d1c5e17b34d497cbda1f754a1ec8552bc'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/97948906dc8e0ea84775e03e35b60a2063c70193'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a1c5672faf8e93e38c2deac3979cc767ca5cf918'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a4fe4eb580bbc7439f649a496d4cf38415a4021c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a9f68d9ed38dd6e5a6c6d75b03d25c1c133e321d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e4c06479d7059888adf2f22bc1ebcf053bf691a2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/e4c4a5074532eaaa14951994a3aad0d479aa7431'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f8a5203596797f394ff3f9aa4005597a92249802'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
epss: 0.00185
epssPercentile: 0.07153
ingestedAt: '2026-06-29T13:42:11.996Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

crypto: af_alg - Cap AEAD AD length to 0x80000000

In order to prevent arithmetic overflows when checking the TX
buffer size, cap the associated data length to 0x80000000.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
