5.5

CVE-2025-71131

crypto: seqiv - Do not use req->iv after crypto_aead_encrypt

In the Linux kernel, the following vulnerability has been resolved:

crypto: seqiv - Do not use req->iv after crypto_aead_encrypt

As soon as crypto_aead_encrypt is called, the underlying request
may be freed by an asynchronous completion.  Thus dereferencing
req->iv after it returns is invalid.

Instead of checking req->iv against info, create a new variable
unaligned_info and use it for that purpose instead.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Linux ≫ Linux Kernel Version >= 2.6.25.1 < 5.10.248
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.198
Linux ≫ Linux Kernel Version >= 5.16 < 6.1.160
Linux ≫ Linux Kernel Version >= 6.2 < 6.6.120
Linux ≫ Linux Kernel Version >= 6.7 < 6.12.64
Linux ≫ Linux Kernel Version >= 6.13 < 6.18.4
Linux ≫ Linux Kernel Version 2.6.25 Update -
Linux ≫ Linux Kernel Version 6.19 Update rc1
Linux ≫ Linux Kernel Version 6.19 Update rc2
Linux ≫ Linux Kernel Version 6.19 Update rc3
Linux ≫ Linux Kernel Version 6.19 Update rc4
Linux ≫ Linux Kernel Version 6.19 Update rc5
Linux ≫ Linux Kernel Version 6.19 Update rc6
Linux ≫ Linux Kernel Version 6.19 Update rc7
Linux ≫ Linux Kernel Version 6.19 Update rc8
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.25% 0.162
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/0279978adec6f1296af66b642cce641c6580be46
Patch
https://git.kernel.org/stable/c/50f196d2bbaee4ab2494bb1b0d294deba292951a
Patch
https://git.kernel.org/stable/c/50fdb78b7c0bcc550910ef69c0984e751cac72fa
Patch
https://git.kernel.org/stable/c/5476f7f8a311236604b78fcc5b2a63b3a61b0169
Patch
https://git.kernel.org/stable/c/ccbb96434d88e32358894c879457b33f7508e798
Patch
https://git.kernel.org/stable/c/18202537856e0fae079fed2c9308780bcff2bb9d
Patch
https://git.kernel.org/stable/c/baf0e2d1e03ddb04781dfe7f22a654d3611f69b2
Patch
https://cert-portal.siemens.com/productcert/html/ssa-019113.html