HIGHCVE-2026-43033Published Modified CNA Linux
CVE-2026-43033: crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption
In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption When decrypting data that is not in-place (src != dst), there is no need to save the high-order sequence bits in dst as it could simply be re-copied from the source. However, the data to be hashed need to be rearranged accordingly. Thanks,
Metrics
- CVSS v3.1
- 7.8
- Severity
- HIGH
- Fixed in
- 0
- Affected Products
- 2
Fix available
0153d5520c3f9fd62e71c7e7f9e34b59cf411e5555.10.2545.15.2045466e7d0cd9e4f9cef9d8f18f18b60e7bc1c77e56.1.1706.6.1376.12.856.18.226.19.127.089fe118b6470119b20c04afc36e45b81a69ea11f8c62f618576519dbed6816fafc623ce592953025cded4002d22177e8deaca1f257ecd932c9582b6bd0c4ff6812386880f30bc64c2921299cc4d7b47fd589abd8b019b07075fda255ceab8c8e950cdb3fe02494114ebf7c8b42777c6cd6982f113bfdbec7
Affected packages
- Linux / Linux< 8c62f618576519dbed6816fafc623ce592953025 (from 104880a6b470958ddc30e139c41aa4f6ed3a5234) · < d589abd8b019b07075fda255ceab8c8e950cdb3f (from 104880a6b470958ddc30e139c41aa4f6ed3a5234) · < 5466e7d0cd9e4f9cef9d8f18f18b60e7bc1c77e5 (from 104880a6b470958ddc30e139c41aa4f6ed3a5234) · < d0c4ff6812386880f30bc64c2921299cc4d7b47f (from 104880a6b470958ddc30e139c41aa4f6ed3a5234) · < 89fe118b6470119b20c04afc36e45b81a69ea11f (from 104880a6b470958ddc30e139c41aa4f6ed3a5234) · < 153d5520c3f9fd62e71c7e7f9e34b59cf411e555 (from 104880a6b470958ddc30e139c41aa4f6ed3a5234)
- Linux / Linux4.3Fixed in 0, 5.10.254, 5.15.204, 6.1.170, 6.6.137, 6.12.85, 6.18.22, 6.19.12, 7.0
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H