Impact
The vulnerability resides in the Linux kernel's AEAD cryptographic helper where an incorrect in‑place copy routine could overwrite memory between separate source and destination buffers. This flaw could corrupt kernel state and potentially allow privilege escalation or denial of service. By reverting the unsafe logic, the kernel now performs a safe out‑of‑place copy of authentication data, eliminating the corruption vector.
Affected Systems
All Linux kernel builds that included the original in‑place copy routine before the revert are impacted. This includes common distributions such as Ubuntu, Debian, Red Hat Enterprise Linux, SUSE Enterprise, Amazon Linux, and other vendors that have not applied subsequent security updates. Systems running an affected kernel version remain at risk until the fix is deployed.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, while the EPSS score of 3 % suggests a low but non‑zero exploitation probability. The vulnerability is listed in CISA’s KEV catalog, confirming active exploitation. Exploitation would require an attacker to trigger the cryptographic helper, typically through local or privileged activity that performs AEAD operations, leading to kernel memory corruption and potentially privilege escalation.
OpenCVE Enrichment
Debian DLA
Debian DSA
Ubuntu USN