Description
In the Linux kernel, the following vulnerability has been resolved:

crypto: acomp - allocate async request context when cloning

ACOMP_REQUEST_ON_STACK() reserves only enough storage for the
synchronous fallback. When an async implementation is selected, callers
clone that stack request before retrying, but acomp_request_clone()
currently copies only the stack-sized object. The clone therefore has no
storage for the async provider request context, and providers such as QAT
write past the allocation through acomp_request_ctx(). KASAN does report
a slab OOB write.

Allocate a zeroed clone large enough for the runtime acomp request size,
copy only the bytes present in the source object, and preserve the
existing fallback-on-allocation-failure behavior. Use the runtime reqsize
because an implementation may adjust it during tfm initialization.
Published: 2026-09-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Local privilege escalation via kernel memory corruption
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel crypto subsystem’s async request cloning routine incorrectly copies only the stack‑sized portion of the request structure, ignoring space required for the async provider’s context. When a provider such as Intel QAT accesses the unallocated area through acomp_request_ctx, it writes past the end of the allocated memory, triggering a slab out‑of‑bounds write detected by KASAN. This flaw can corrupt kernel memory, enabling an attacker to execute arbitrary code or crash the system.

Affected Systems

All Linux kernel releases that include the vulnerable crypto acomp implementation are affected; the vendor listing simply references Linux. Specific affected versions are not enumerated in the data, but the patch implementing the fix is present in the kernel source as commit 889fa17a0af09ff93a9166abc82ee7a654faa49b. System administrators should check if their running kernel includes that commit before a full upgrade.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity. Based on the description, it is inferred that an attacker would need to trigger the async crypto provider path, which typically requires local system access and a suitable crypto workload, so the attack vector is local. The EPSS score is reported as less than 1%, indicating a very low likelihood of widespread exploitation at the present time and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Nonetheless, because this is a kernel buffer overrun that can lead to local privilege escalation, the risk to systems that expose the affected crypto subsystem is significant. No public exploit is currently known, but the high severity of the bug warrants prompt mitigation.

Generated by OpenCVE AI on September 20, 2026 at 04:30 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that includes the patch adding the correct allocation for the async request clone (commit 889fa17a0af09ff93a9166abc82ee7a654faa49b).
  • If an immediate kernel upgrade is not possible, prevent the problematic async crypto provider modules such as QAT from loading (e.g., remove/blacklist the modules or adjust module loading policies).
  • Continue to monitor kernel logs for KASAN out‑of‑bounds warnings or application crashes that may indicate an attempt to exploit the flaw.

Generated by OpenCVE AI on September 20, 2026 at 04:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
CWE-122

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: crypto: acomp - allocate async request context when cloning ACOMP_REQUEST_ON_STACK() reserves only enough storage for the synchronous fallback. When an async implementation is selected, callers clone that stack request before retrying, but acomp_request_clone() currently copies only the stack-sized object. The clone therefore has no storage for the async provider request context, and providers such as QAT write past the allocation through acomp_request_ctx(). KASAN does report a slab OOB write. Allocate a zeroed clone large enough for the runtime acomp request size, copy only the bytes present in the source object, and preserve the existing fallback-on-allocation-failure behavior. Use the runtime reqsize because an implementation may adjust it during tfm initialization.
Title crypto: acomp - allocate async request context when cloning
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-18T17:52:52.872Z

Reserved: 2026-09-11T19:38:34.784Z

Link: CVE-2026-90069

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:16:55.830

Modified: 2026-09-18T18:17:40.710

Link: CVE-2026-90069

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T04:30:18Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

  • CWE-122

    Heap-based Buffer Overflow