Description
In the Linux kernel, the following vulnerability has been resolved:

crypto: keembay - Fix AEAD unregister count in error path

register_aes_algs() registers the AEAD algorithms before registering the
skcipher algorithms. If skcipher registration fails, the function unwinds
the earlier AEAD registration with crypto_engine_unregister_aeads(), but it
passes ARRAY_SIZE(algs), which is the skcipher table size.

Use ARRAY_SIZE(algs_aead) for the AEAD unwind path so the unregister helper
iterates over the same table that was registered. Also clarify the nearby
comment: the crypto registration helpers clean up algorithms registered
within the same call, while this function must still unwind earlier
successful registration steps.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via Kernel Crash
Action: Patch Kernel
AI Analysis

Impact

An error‑path bug in the Linux kernel’s keembay module causes the unregistration helper to use the wrong array size when cleaning up AEAD algorithm registrations. If a skcipher registration fails, the code unwinds the earlier AEAD registrations with a size that matches the skcipher table instead of the AEAD table, which can leave residual entries or attempt to remove more items than were registered. This mismatch can corrupt internal data structures in the kernel’s cryptographic subsystem, potentially leading to a kernel crash or other instability. The primary impact is the loss of system availability through a denial‑of‑service condition. Based on the description, the weakness resides in improper cleanup logic of cryptographic algorithm registration.

Affected Systems

All Linux kernel builds that include the buggy keembay registration logic are vulnerable, as the flaw exists in any kernel prior to the patch commits referenced in the provided Git URLs. The vulnerability is present across distributions that ship those kernels. The asset is the kernel itself, making the entire host system potentially affected.

Risk and Exploitability

The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. The flaw is not publicly exploitable remotely and would require an attacker with sufficient privileges to trigger a registration failure—such as an administrator loading a kernel module or otherwise forcing a cryptographic registration error—to trigger the denial‑of‑service event. Without such privilege, the risk to a typical user is negligible.

Generated by OpenCVE AI on September 19, 2026 at 09:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that incorporates the keembay AEAD cleanup fix, such as the latest stable release from the distribution’s official repository
  • Reboot the system after the kernel upgrade to ensure the new kernel and the corrected registration logic are active
  • If running custom or third‑party kernel modules that use keembay AEAD, disable or remove them until the kernel update is applied to reduce the attack surface

Generated by OpenCVE AI on September 19, 2026 at 09:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-129
CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: crypto: keembay - Fix AEAD unregister count in error path register_aes_algs() registers the AEAD algorithms before registering the skcipher algorithms. If skcipher registration fails, the function unwinds the earlier AEAD registration with crypto_engine_unregister_aeads(), but it passes ARRAY_SIZE(algs), which is the skcipher table size. Use ARRAY_SIZE(algs_aead) for the AEAD unwind path so the unregister helper iterates over the same table that was registered. Also clarify the nearby comment: the crypto registration helpers clean up algorithms registered within the same call, while this function must still unwind earlier successful registration steps.
Title crypto: keembay - Fix AEAD unregister count in error path
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:50.792Z

Reserved: 2026-09-17T16:02:15.089Z

Link: CVE-2026-93155

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:10.813

Modified: 2026-09-17T17:18:10.813

Link: CVE-2026-93155

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:00:21Z

Weaknesses
  • CWE-129

    Improper Validation of Array Index

  • CWE-665

    Improper Initialization