8.8
CVE-2026-68125
- EPSS 0.32%
- Veröffentlicht 10.08.2026 11:58:46
- Zuletzt bearbeitet 19.08.2026 17:20:30
- Erkennungen
mac802154: llsec: reject frames shorter than the authentication tag
In the Linux kernel, the following vulnerability has been resolved: mac802154: llsec: reject frames shorter than the authentication tag llsec_do_decrypt_auth() computes the associated-data length for the AEAD request as assoclen += datalen - authlen; where datalen is the number of bytes after the MAC header and authlen (4, 8 or 16) is the length of the authentication tag. Nothing verifies that the frame actually carries at least authlen payload bytes. A secured frame whose payload is shorter than the tag makes datalen - authlen negative; assoclen is then passed to aead_request_set_ad() as an unsigned value close to 4 GiB, so crypto_aead_decrypt() walks far off the end of the scatterlist that only spans the real frame. The frame is fully attacker-controlled and reaches this path from any IEEE 802.15.4 peer in radio range. Reject frames whose payload is shorter than the authentication tag before the subtraction. Dynamically reproduced on a KASAN kernel as a general-protection-fault in the AEAD scatterwalk, and the fix confirmed.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
4c14a2fb5d143e4ed94143be2b8c1961b47df9af
Version <
f27ce82eb04960465df71634b196a48a4ecafd50
Status
affected
Version
4c14a2fb5d143e4ed94143be2b8c1961b47df9af
Version <
2d6b42a61373144298070668fddf06efe79cf2ff
Status
affected
Version
4c14a2fb5d143e4ed94143be2b8c1961b47df9af
Version <
ec7e62d77193131227df49d654d118fdf5a59892
Status
affected
Version
4c14a2fb5d143e4ed94143be2b8c1961b47df9af
Version <
5bbf0cd9b6a7076af86c75e87e180099be2e11ae
Status
affected
Version
4c14a2fb5d143e4ed94143be2b8c1961b47df9af
Version <
de80808f37d99c6dc67bb6f97eea00c8f57a8821
Status
affected
Version
4c14a2fb5d143e4ed94143be2b8c1961b47df9af
Version <
f20dedce0429b293d4bad604e0d3f65d8ac96c83
Status
affected
Version
4c14a2fb5d143e4ed94143be2b8c1961b47df9af
Version <
e09e0301d616c1ef38a5e64e8e4326fd39df13cc
Status
affected
Version
4c14a2fb5d143e4ed94143be2b8c1961b47df9af
Version <
fd3a3f28ed60c6af4b2a39933b151d6b27842c3b
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
3.16
Status
affected
Version
0
Version <
3.16
Status
unaffected
Version <=
5.10.*
Version
5.10.265
Status
unaffected
Version <=
5.15.*
Version
5.15.216
Status
unaffected
Version <=
6.1.*
Version
6.1.183
Status
unaffected
Version <=
6.6.*
Version
6.6.148
Status
unaffected
Version <=
6.12.*
Version
6.12.101
Status
unaffected
Version <=
6.18.*
Version
6.18.42
Status
unaffected
Version <=
7.1.*
Version
7.1.6
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.25 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/5bbf0cd9b6a7076af86c75e87e180099be2e11ae
https://git.kernel.org/stable/c/de80808f37d99c6dc67bb6f97eea00c8f57a8821
https://git.kernel.org/stable/c/f20dedce0429b293d4bad604e0d3f65d8ac96c83
https://git.kernel.org/stable/c/e09e0301d616c1ef38a5e64e8e4326fd39df13cc
https://git.kernel.org/stable/c/fd3a3f28ed60c6af4b2a39933b151d6b27842c3b
https://git.kernel.org/stable/c/2d6b42a61373144298070668fddf06efe79cf2ff
https://git.kernel.org/stable/c/ec7e62d77193131227df49d654d118fdf5a59892
https://git.kernel.org/stable/c/f27ce82eb04960465df71634b196a48a4ecafd50