CVE-2026-80522 PUBLISHED

crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req()

Assigner: Linux
Reserved: 26.08.2026 Published: 26.08.2026 Updated: 26.08.2026

In the Linux kernel, the following vulnerability has been resolved:

crypto: tegra - fix rctx->cryptlen calculation in tegra_gcm_do_one_req()

Perform rctx->cryptlen calculation in tegra_gcm_do_one_req() the same way it is done in tegra_ccm_crypt_init(). The current formulae may lead to a crash if a caller does not call tegra_gcm_setauthsize() and so ctx->authsize remains zero. Then a decrypt operation with incorrect rctx->cryptlen will lead to a write beyound rctx->dst_sg buffer.

As a follow-up cleanup delete struct tegra_aead_ctx->authsize field since it appears to be completely unused. Also simplify tegra_ccm_setauthsize() and tegra_gcm_setauthsize() functions respectively.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 0880bb3b00c855fc244b7177ffdaafef4d0aa1e0 to cd6991001bf0681ed0bcf21f9cc3d261d749b2bb (excl.)
  • affected from 0880bb3b00c855fc244b7177ffdaafef4d0aa1e0 to 99a18e1d979e0fad3aaf9c65ae6696897c1d9869 (excl.)
  • affected from 0880bb3b00c855fc244b7177ffdaafef4d0aa1e0 to c6237834d9994de209cb90c7a2c461247bce8e90 (excl.)
  • affected from 0880bb3b00c855fc244b7177ffdaafef4d0aa1e0 to 360f2974fcea49c61f6d6f81554741a9eeee7168 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.10 is affected
  • unaffected from 0 to 6.10 (excl.)
  • unaffected from 6.12.105 to 6.12.* (incl.)
  • unaffected from 6.18.46 to 6.18.* (incl.)
  • unaffected from 7.1.10 to 7.1.* (incl.)
  • unaffected from 7.2 to * (incl.)

References