8.8

CVE-2026-68125

mac802154: llsec: reject frames shorter than the authentication tag

In the Linux kernel, the following vulnerability has been resolved:

mac802154: llsec: reject frames shorter than the authentication tag

llsec_do_decrypt_auth() computes the associated-data length for the
AEAD request as

	assoclen += datalen - authlen;

where datalen is the number of bytes after the MAC header and authlen
(4, 8 or 16) is the length of the authentication tag. Nothing verifies
that the frame actually carries at least authlen payload bytes. A
secured frame whose payload is shorter than the tag makes
datalen - authlen negative; assoclen is then passed to
aead_request_set_ad() as an unsigned value close to 4 GiB, so
crypto_aead_decrypt() walks far off the end of the scatterlist that
only spans the real frame.

The frame is fully attacker-controlled and reaches this path from any
IEEE 802.15.4 peer in radio range. Reject frames whose payload is
shorter than the authentication tag before the subtraction.

Dynamically reproduced on a KASAN kernel as a general-protection-fault
in the AEAD scatterwalk, and the fix confirmed.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 4c14a2fb5d143e4ed94143be2b8c1961b47df9af
Version < f27ce82eb04960465df71634b196a48a4ecafd50
Status affected
Version 4c14a2fb5d143e4ed94143be2b8c1961b47df9af
Version < 2d6b42a61373144298070668fddf06efe79cf2ff
Status affected
Version 4c14a2fb5d143e4ed94143be2b8c1961b47df9af
Version < ec7e62d77193131227df49d654d118fdf5a59892
Status affected
Version 4c14a2fb5d143e4ed94143be2b8c1961b47df9af
Version < 5bbf0cd9b6a7076af86c75e87e180099be2e11ae
Status affected
Version 4c14a2fb5d143e4ed94143be2b8c1961b47df9af
Version < de80808f37d99c6dc67bb6f97eea00c8f57a8821
Status affected
Version 4c14a2fb5d143e4ed94143be2b8c1961b47df9af
Version < f20dedce0429b293d4bad604e0d3f65d8ac96c83
Status affected
Version 4c14a2fb5d143e4ed94143be2b8c1961b47df9af
Version < e09e0301d616c1ef38a5e64e8e4326fd39df13cc
Status affected
Version 4c14a2fb5d143e4ed94143be2b8c1961b47df9af
Version < fd3a3f28ed60c6af4b2a39933b151d6b27842c3b
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 3.16
Status affected
Version 0
Version < 3.16
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.148
Status unaffected
Version <= 6.12.*
Version 6.12.101
Status unaffected
Version <= 6.18.*
Version 6.18.42
Status unaffected
Version <= 7.1.*
Version 7.1.6
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.25
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/5bbf0cd9b6a7076af86c75e87e180099be2e11ae
https://git.kernel.org/stable/c/de80808f37d99c6dc67bb6f97eea00c8f57a8821
https://git.kernel.org/stable/c/f20dedce0429b293d4bad604e0d3f65d8ac96c83
https://git.kernel.org/stable/c/e09e0301d616c1ef38a5e64e8e4326fd39df13cc
https://git.kernel.org/stable/c/fd3a3f28ed60c6af4b2a39933b151d6b27842c3b
https://git.kernel.org/stable/c/2d6b42a61373144298070668fddf06efe79cf2ff
https://git.kernel.org/stable/c/ec7e62d77193131227df49d654d118fdf5a59892
https://git.kernel.org/stable/c/f27ce82eb04960465df71634b196a48a4ecafd50