Description
In the Linux kernel, the following vulnerability has been resolved:

crypto: qce - fix error path in devm_qce_register_algs

If ops->register_algs() fails, the error path repeatedly calls the same
ops->unregister_algs() from the failed registration. Use the loop index
to unregister the previously registered algorithms instead.
Published: 2026-08-26
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Immediate Patch
AI Analysis

Impact

A defect in the Linux kernel’s qce cryptographic driver causes the error handling logic to repeatedly call the same unregister function when algorithm registration fails. The bug results in an incorrect cleanup loop that may leave resources improperly released, potentially leading to kernel instability such as a crash that denies service to users.

Affected Systems

All Linux kernel releases that ship the qce cryptographic module and have not yet incorporated the commit correcting the error path are affected. This includes the core Linux kernel provided by all major distributions and any custom kernel builds that include the qce driver.

Risk and Exploitability

The CVSS score of 7.8 reflects high severity, but the EPSS score is very low at below 1%, and the vulnerability is not listed in CISA KEV. No public exploits are documented. Exploitation requires local or privileged kernel execution to trigger the erroneous registration routine; an attacker would need to induce a registration failure or otherwise cause the faulty loop to execute. In environments where the kernel remains unpatched and the qce module is active, the risk is moderate to high due to the potential for a kernel crash that would shut down services and deny availability.

Generated by OpenCVE AI on August 28, 2026 at 08:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that contains the commit which corrects the erroneous unregister loop in devm_qce_register_algs.
  • If an upgrade cannot be performed immediately, blacklist the qce module by adding "blacklist qce" to /etc/modprobe.d/blacklist.conf so it never loads, preventing execution of the vulnerable code.
  • Until a patch or module disablement is effected, verify that no third‑party applications or services invoke QCE algorithm registration during boot or runtime and disable or remove such functionality to avoid triggering the flaw.

Generated by OpenCVE AI on August 28, 2026 at 08:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4777-1 linux security update
History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-763
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 27 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-415

Thu, 27 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-390
CWE-668

Thu, 27 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 26 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-390
CWE-668

Wed, 26 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: crypto: qce - fix error path in devm_qce_register_algs If ops->register_algs() fails, the error path repeatedly calls the same ops->unregister_algs() from the failed registration. Use the loop index to unregister the previously registered algorithms instead.
Title crypto: qce - fix error path in devm_qce_register_algs
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-27T05:01:50.972Z

Reserved: 2026-08-26T14:34:25.767Z

Link: CVE-2026-80565

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T15:17:11.550

Modified: 2026-08-27T06:17:41.390

Link: CVE-2026-80565

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-26T00:00:00Z

Links: CVE-2026-80565 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T09:00:10Z

Weaknesses