← Back to CVE List
CVE-2026-90069NVD
Vulnerability Summary
In the Linux kernel, the following vulnerability has been resolved:
crypto: acomp - allocate async request context when cloning
ACOMP_REQUEST_ON_STACK() reserves only enough storage for the
synchronous fallback. When an async implementation is selected, callers
clone that stack request before retrying, but acomp_request_clone()
currently copies only the stack-sized object. The clone therefore has no
storage for the async provider request context, and providers such as QAT
write past the allocation through acomp_request_ctx(). KASAN does report
a slab OOB write.
Allocate a zeroed clone large enough for the runtime acomp request size,
copy only the bytes present in the source object, and preserve the
existing fallback-on-allocation-failure behavior. Use the runtime reqsize
because an implementation may adjust it during tfm initialization.
crypto: acomp - allocate async request context when cloning
ACOMP_REQUEST_ON_STACK() reserves only enough storage for the
synchronous fallback. When an async implementation is selected, callers
clone that stack request before retrying, but acomp_request_clone()
currently copies only the stack-sized object. The clone therefore has no
storage for the async provider request context, and providers such as QAT
write past the allocation through acomp_request_ctx(). KASAN does report
a slab OOB write.
Allocate a zeroed clone large enough for the runtime acomp request size,
copy only the bytes present in the source object, and preserve the
existing fallback-on-allocation-failure behavior. Use the runtime reqsize
because an implementation may adjust it during tfm initialization.
CVSS v3.1 Base Metrics — Score 7.8 (HIGH)
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Linux Linux >= 097c432caaa6d91f87732fe991cb08139e31101a and < d48197cbd5d3476c7deea644972e9ec510865ec2
- Linux Linux >= 097c432caaa6d91f87732fe991cb08139e31101a and < 889fa17a0af09ff93a9166abc82ee7a654faa49b
- Linux Linux >= 097c432caaa6d91f87732fe991cb08139e31101a and < ee440d4fc0d2f15894ab1f64c474a3adbc858880
- Linux Linux >= 6.16
- Linux Linux d48197cbd5d3476c7deea644972e9ec510865ec2
- Linux Linux 889fa17a0af09ff93a9166abc82ee7a654faa49b
- Linux Linux ee440d4fc0d2f15894ab1f64c474a3adbc858880