---
id: CVE-2026-80836
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  crypto: virtio - bound the akcipher result length

  virtio_crypto_dataq_akcipher_callback() sets the result length from the
  device-reported response length without bound…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  crypto: virtio - bound the akcipher result length

  virtio_crypto_dataq_akcipher_callback() sets the result length from the
  device-reported response length without bound…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= a36bd0ad9fbf69d0d711b1c105954ce8d6cc144a <
    12c4f29e97f31b013f77ad65ba7daeb02aaa6abe
  - >-
    Linux >= a36bd0ad9fbf69d0d711b1c105954ce8d6cc144a <
    5545de5050cbc3594506d74f2c392b0716cf8bca
  - >-
    Linux >= a36bd0ad9fbf69d0d711b1c105954ce8d6cc144a <
    3fda114a42f1510a4ec8a0b17a0cfc997952ccc2
  - >-
    Linux >= a36bd0ad9fbf69d0d711b1c105954ce8d6cc144a <
    1f9f877b1ef1fbd4ee95571cddf39c8002cee252
  - >-
    Linux >= a36bd0ad9fbf69d0d711b1c105954ce8d6cc144a <
    f77a956f6a19f9463ef1527c9d0cda50dded6b92
  - Linux 5.19
published: '2026-09-04'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T14:17:20.680'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80836'
references:
  - url: 'https://git.kernel.org/stable/c/12c4f29e97f31b013f77ad65ba7daeb02aaa6abe'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/1f9f877b1ef1fbd4ee95571cddf39c8002cee252'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3fda114a42f1510a4ec8a0b17a0cfc997952ccc2'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5545de5050cbc3594506d74f2c392b0716cf8bca'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/f77a956f6a19f9463ef1527c9d0cda50dded6b92'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
epss: 0.00209
epssPercentile: 0.09781
ingestedAt: '2026-09-21T13:37:22.836Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

crypto: virtio - bound the akcipher result length

virtio_crypto_dataq_akcipher_callback() sets the result length from the
device-reported response length without bounding it to the destination
buffer, which was allocated for the original request length.
sg_copy_from_buffer() then reads that many bytes from the destination
buffer; a backend reporting a larger length over-reads adjacent kernel
heap into the caller's scatterlist (an out-of-bounds read).

Clamp the reported length to the originally requested destination length.
A conforming device reports no more than that, so valid results are
unaffected.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
