7.8

CVE-2026-89607

ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet

In the Linux kernel, the following vulnerability has been resolved:

ecryptfs: reject oversized encrypted_key_size in parse_tag_3_packet

parse_tag_3_packet() set encrypted_key_size from the Tag 3 packet body
without bounding it against ECRYPTFS_MAX_KEY_BYTES (64). When
encrypted_key_size > 64, decrypt_passphrase_encrypted_session_key()
sets decrypted_key_size = encrypted_key_size and performs two
out-of-bounds writes:

1. crypto_skcipher_decrypt() writes encrypted_key_size bytes into
   decrypted_key[64] via scatterlist, overflowing into the parent
   ecryptfs_auth_tok struct.
2. memcpy(crypt_stat->key, decrypted_key, decrypted_key_size) writes
   into crypt_stat->key[64], corrupting root_iv, keysig_list, and
   mutexes in ecryptfs_crypt_stat.

Only AES-192 (cipher code 0x08) enables this because it sets
crypt_stat->key_size = 24 independently of encrypted_key_size,
allowing crypto_skcipher_setkey() to succeed while encrypted_key_size
exceeds ECRYPTFS_MAX_KEY_BYTES.

The PKI decryption path (parse_tag_65_packet) already validates
decrypted_key_size <= ECRYPTFS_MAX_KEY_BYTES; the passphrase path
omits this check.

Bound encrypted_key_size against ECRYPTFS_MAX_KEY_BYTES (64) rather
than ECRYPTFS_MAX_ENCRYPTED_KEY_BYTES (512). The 64-byte limit also
protects the 512-byte encrypted_key[] buffer, so the former 512-byte
check is removed as redundant.

[tyhicks: Adjust the code comment to refer to macros representing the
 buffer sizes rather than mentioning the buffer size values since they
 may change in the future]
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 237fead619984cc48818fe12ee0ceada3f55b012
Version < 2cd21340163494d312836c77c9fbfe2530b3d075
Status affected
Version 237fead619984cc48818fe12ee0ceada3f55b012
Version < e2152d491ae62d96a32ed59778680a242af1fbc6
Status affected
Version 237fead619984cc48818fe12ee0ceada3f55b012
Version < d2802414081184f79a619ede178aeef3aa989793
Status affected
Version 237fead619984cc48818fe12ee0ceada3f55b012
Version < 33e050cac841498b5175f0f385eee903fd98863c
Status affected
Version 237fead619984cc48818fe12ee0ceada3f55b012
Version < ccd13eff0e7356d2aa28b127b577e4e5ad4563f5
Status affected
Version 237fead619984cc48818fe12ee0ceada3f55b012
Version < 14cb36a500a5a3afbc955dbf69dabc565f1a3b26
Status affected
Version 237fead619984cc48818fe12ee0ceada3f55b012
Version < a419c9ebfc9a40ee56aaad6dc68bfd67d400817b
Status affected
Version 237fead619984cc48818fe12ee0ceada3f55b012
Version < 5babe9c177c364521e3e682b949c5a8c47f4a441
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 2.6.19
Status affected
Version 0
Version < 2.6.19
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.4
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.058
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/ccd13eff0e7356d2aa28b127b577e4e5ad4563f5
https://git.kernel.org/stable/c/14cb36a500a5a3afbc955dbf69dabc565f1a3b26
https://git.kernel.org/stable/c/a419c9ebfc9a40ee56aaad6dc68bfd67d400817b
https://git.kernel.org/stable/c/5babe9c177c364521e3e682b949c5a8c47f4a441
https://git.kernel.org/stable/c/2cd21340163494d312836c77c9fbfe2530b3d075
https://git.kernel.org/stable/c/33e050cac841498b5175f0f385eee903fd98863c
https://git.kernel.org/stable/c/d2802414081184f79a619ede178aeef3aa989793
https://git.kernel.org/stable/c/e2152d491ae62d96a32ed59778680a242af1fbc6