Description
In the Linux kernel, the following vulnerability has been resolved:

crypto: iaa - unmap dst before software fallback on decompress

On a hardware analytics error, decompress retries through the software
fallback, which writes req->dst with the CPU while it is still mapped
DMA_FROM_DEVICE. With SWIOTLB active the later dma_unmap_sg() copies the
stale bounce buffer over req->dst, corrupting the result.

Unmap before the fallback runs. The async path unmaps inline; the sync
path signals the retry with -EAGAIN so iaa_comp_adecompress() runs the
fallback after unmapping.
Published: 2026-09-11
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Memory corruption in Linux kernel crypto decompression
Action: Patch
AI Analysis

Impact

An out‑of‑bounds write occurs in the Linux kernel crypto IAAs decompression routine when a hardware error forces a fallback to software decompression. While SWIOTLB is active, the destination buffer remains mapped for DMA_FROM_DEVICE and the software path writes over stale data, corrupting the output. This flaw is a classic memory corruption bug (CWE‑787) that can lead to data integrity problems and potentially disrupt cryptographic operations.

Affected Systems

All Linux kernel builds that include the crypto IAAs decompression feature and have not applied the upstream change are affected. The issue is present across all vendor distributions that ship the kernel without the patch; no specific version numbers are listed in the CNA data.

Risk and Exploitability

The CVSS score of 9.1 signals a high‑severity flaw, while the EPSS score of less than 1 % reflects a very low but non‑zero likelihood of exploitation. The vulnerability is not flagged in CISA’s KEV catalog. Real‑world exploitation would require an attacker to induce a hardware error that triggers the decompress retry with SWIOTLB enabled—an action that is non‑trivial and typically demands privileged or specialized hardware. Consequently, while the potential impact is severe, the probability of exploitation in the wild remains low.

Generated by OpenCVE AI on September 21, 2026 at 02:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest kernel update that contains the IAAs decompression fix for the Linux kernel crypto module.
  • If an update is not yet available, temporarily disable SWIOTLB in the kernel configuration or via relevant sysctl settings to prevent the stale DMA condition while waiting for the patch.
  • Consider switching to a hardware cryptographic accelerator that bypasses the IAAs decompression path, or restart affected services to reload the crypto module without engaging the decompression logic.

Generated by OpenCVE AI on September 21, 2026 at 02:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 21 Sep 2026 13:30:00 +0000


Sun, 13 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: crypto: iaa - unmap dst before software fallback on decompress On a hardware analytics error, decompress retries through the software fallback, which writes req->dst with the CPU while it is still mapped DMA_FROM_DEVICE. With SWIOTLB active the later dma_unmap_sg() copies the stale bounce buffer over req->dst, corrupting the result. Unmap before the fallback runs. The async path unmaps inline; the sync path signals the retry with -EAGAIN so iaa_comp_adecompress() runs the fallback after unmapping.
Title crypto: iaa - unmap dst before software fallback on decompress
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-21T13:14:20.481Z

Reserved: 2026-08-26T14:34:25.803Z

Link: CVE-2026-80945

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:19:00.057

Modified: 2026-09-21T14:17:21.567

Link: CVE-2026-80945

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:42:16Z

Links: CVE-2026-80945 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T03:00:12Z

Weaknesses