Description
In the Linux kernel, the following vulnerability has been resolved:

crypto: qce - fix error path in devm_qce_register_algs

If ops->register_algs() fails, the error path repeatedly calls the same
ops->unregister_algs() from the failed registration. Use the loop index
to unregister the previously registered algorithms instead.
Published: 2026-08-26
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An incorrect error handling path in the Linux kernel’s qce crypto driver causes the same unregister operation to be invoked repeatedly when an algorithm registration fails. The loop uses the same index for all attempts instead of the actual index of previously registered algorithms, which can leave the kernel in an inconsistent state. This flaw prevents proper cleanup of resources and may lead to memory corruption, kernel panic, or denial of service if the subsystem is repeatedly attempted to be initialized.

Affected Systems

The flaw is present in the generic Linux kernel across all distributions that rely on the qce crypto module by default. There are no vendor‑specific product variations listed; the issue applies universally to any kernel version that includes the qce driver before the fix was committed.

Risk and Exploitability

Because the vulnerability requires an operation that derails the kernel’s cryptographic module registration, it is a local‑kernel problem that would typically be exercised by privileged code such as a kernel module or system service. No publicly available KEV entry or EPSS score is reported, and the CVSS metrics are not disclosed. The impact is primarily a potential denial of service or data corruption within the affected host. The description suggests the flaw may be triggered during normal system startup on a vulnerable kernel, but the lack of a publicly exploitable path reduces the likelihood of widespread exploitation at this time.

Generated by OpenCVE AI on August 26, 2026 at 15:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that includes the commit that fixes the error path in devm_qce_register_algs.
  • If an immediate kernel upgrade is not possible, disable or unload the qce crypto module to prevent the faulty registration logic from executing during boot.
  • Monitor kernel logs for "register_algs" or "unregister_algs" errors and verify that the loop no longer re‑invokes unregister on the same index; consider applying kernel hardening settings such as CONFIG_CRYPTO_FIPS or restricting module loading to trusted modules.

Generated by OpenCVE AI on August 26, 2026 at 15:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 26 Aug 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-390
CWE-668

Wed, 26 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: crypto: qce - fix error path in devm_qce_register_algs If ops->register_algs() fails, the error path repeatedly calls the same ops->unregister_algs() from the failed registration. Use the loop index to unregister the previously registered algorithms instead.
Title crypto: qce - fix error path in devm_qce_register_algs
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-08-26T14:37:28.953Z

Reserved: 2026-08-26T14:34:25.767Z

Link: CVE-2026-80565

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-26T15:17:11.550

Modified: 2026-08-26T15:17:11.550

Link: CVE-2026-80565

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T22:45:03Z

Weaknesses
  • CWE-390

    Detection of Error Condition Without Action

  • CWE-668

    Exposure of Resource to Wrong Sphere