HIGHCVE-2026-23222Published Modified CNA Linux
CVE-2026-23222: crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly
In the Linux kernel, the following vulnerability has been resolved: crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly The existing allocation of scatterlists in omap_crypto_copy_sg_lists() was allocating an array of scatterlist pointers, not scatterlist objects, resulting in a 4x too small allocation. Use sizeof(*new_sg) to get the correct object size.
Metrics
- CVSS v3.1
- 7.8
- Severity
- HIGH
- Fixed in
- 0
- Affected Products
- 2
Fix available
01562b1fb7e17c1b3addb15e125c718b2be7f55122ed27b5a1174351148c3adbfc0cd86d54072ba2e31aff96a41ae6f1f1687c065607875a27c364da85.10.2515.15.2016.1.1646.6.1256.12.726.18.116.19.16edf8df4bd29f7bfd245b67b2c31d905f1cfc14b7.079f95b51d4278044013672c27519ae88d07013d8953c81941b0ad373674656b8767c00234ebf17acc184341920ed78b6466360ed7b45b8922586c38fd1836c628cb72734eb5f7dfd4c996a9c18bba3ad
Affected packages
- Linux / Linux< 953c81941b0ad373674656b8767c00234ebf17ac (from 74ed87e7e7f7197137164738dd0610ccd5ec5ed1) · < 31aff96a41ae6f1f1687c065607875a27c364da8 (from 74ed87e7e7f7197137164738dd0610ccd5ec5ed1) · < 79f95b51d4278044013672c27519ae88d07013d8 (from 74ed87e7e7f7197137164738dd0610ccd5ec5ed1) · < 6edf8df4bd29f7bfd245b67b2c31d905f1cfc14b (from 74ed87e7e7f7197137164738dd0610ccd5ec5ed1) · < c184341920ed78b6466360ed7b45b8922586c38f (from 74ed87e7e7f7197137164738dd0610ccd5ec5ed1) · < 2ed27b5a1174351148c3adbfc0cd86d54072ba2e (from 74ed87e7e7f7197137164738dd0610ccd5ec5ed1)
- Linux / Linux4.13Fixed in 0, 5.10.251, 5.15.201, 6.1.164, 6.6.125, 6.12.72, 6.18.11, 6.19.1, 7.0
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H