CVE-2026-93155 is a vulnerability in Linux Kernel
Published on September 17, 2026
crypto: keembay - Fix AEAD unregister count in error path
In the Linux kernel, the following vulnerability has been resolved:
crypto: keembay - Fix AEAD unregister count in error path
register_aes_algs() registers the AEAD algorithms before registering the
skcipher algorithms. If skcipher registration fails, the function unwinds
the earlier AEAD registration with crypto_engine_unregister_aeads(), but it
passes ARRAY_SIZE(algs), which is the skcipher table size.
Use ARRAY_SIZE(algs_aead) for the AEAD unwind path so the unregister helper
iterates over the same table that was registered. Also clarify the nearby
comment: the crypto registration helpers clean up algorithms registered
within the same call, while this function must still unwind earlier
successful registration steps.
Products Associated with CVE-2026-93155
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 88574332451380f4b51f6ca88ab9810e714bfb9b and below 27ec91c29ee155cc507b2f56221fc6fab65dbb51 is affected.
- Version 88574332451380f4b51f6ca88ab9810e714bfb9b and below 5607b101d86cbee8dd1ffab784495c880ca73383 is affected.
- Version 88574332451380f4b51f6ca88ab9810e714bfb9b and below 5bbb726d27ff6dff750264e51aa665538394d0f8 is affected.
- Version 88574332451380f4b51f6ca88ab9810e714bfb9b and below a3217fe7998622728a53dff405615e0971949eaf is affected.
- Version 88574332451380f4b51f6ca88ab9810e714bfb9b and below e264401ce4776a288524e5b87593d4d864147115 is affected.
- Version 5.11 is affected.
- Before 5.11 is unaffected.
- Version 6.6.157, <= 6.6.* is unaffected.
- Version 6.12.110, <= 6.12.* is unaffected.
- Version 6.18.52, <= 6.18.* is unaffected.
- Version 7.2.6, <= 7.2.* is unaffected.
- Version 7.3-rc1, <= * is unaffected.