Linux kernel: crypto algif_aead RX size check flaw due to missing tag
CVE-2026-43077 Published on May 6, 2026
crypto: algif_aead - Fix minimum RX size check for decryption
In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Fix minimum RX size check for decryption
The check for the minimum receive buffer size did not take the
tag size into account during decryption. Fix this by adding the
required extra length.
Products Associated with CVE-2026-43077
stack.watch emails you whenever new vulnerabilities are published in Linux Kernel or Canonical Ubuntu Linux. Just hit a watch button to start following.
Affected Versions
Linux:- Version d887c52d6ae43aeebd249b5f2f1333e60236aa60 and below 74a66fdb5282d89e348b00c42cfca3a936946d94 is affected.
- Version d887c52d6ae43aeebd249b5f2f1333e60236aa60 and below fd427dd84f224309afbcc2cb67c7bb770a01265c is affected.
- Version d887c52d6ae43aeebd249b5f2f1333e60236aa60 and below 1c76b5675119f694458293a2a81f40731c69bd32 is affected.
- Version d887c52d6ae43aeebd249b5f2f1333e60236aa60 and below e86ab1e5661386a874fbb8551f0c04b8e9f8ad22 is affected.
- Version d887c52d6ae43aeebd249b5f2f1333e60236aa60 and below af2fa2fbbced26129813274b8b3f7705f280e174 is affected.
- Version d887c52d6ae43aeebd249b5f2f1333e60236aa60 and below 78cea133daf721698876e56135049a96d39d610a is affected.
- Version d887c52d6ae43aeebd249b5f2f1333e60236aa60 and below 3afdc15d6173614d7d834517d9b65e7aa5a08548 is affected.
- Version d887c52d6ae43aeebd249b5f2f1333e60236aa60 and below 3d14bd48e3a77091cbce637a12c2ae31b4a1687c is affected.
- Version 4.14 is affected.
- Before 4.14 is unaffected.
- Version 5.10.254, <= 5.10.* is unaffected.
- Version 5.15.204, <= 5.15.* is unaffected.
- Version 6.1.170, <= 6.1.* is unaffected.
- Version 6.6.136, <= 6.6.* is unaffected.
- Version 6.12.83, <= 6.12.* is unaffected.
- Version 6.18.24, <= 6.18.* is unaffected.
- Version 6.19.14, <= 6.19.* is unaffected.
- Version 7.0, <= * is unaffected.