Impact
An error‑path bug in the Linux kernel’s keembay module causes the unregistration helper to use the wrong array size when cleaning up AEAD algorithm registrations. If a skcipher registration fails, the code unwinds the earlier AEAD registrations with a size that matches the skcipher table instead of the AEAD table, which can leave residual entries or attempt to remove more items than were registered. This mismatch can corrupt internal data structures in the kernel’s cryptographic subsystem, potentially leading to a kernel crash or other instability. The primary impact is the loss of system availability through a denial‑of‑service condition. Based on the description, the weakness resides in improper cleanup logic of cryptographic algorithm registration.
Affected Systems
All Linux kernel builds that include the buggy keembay registration logic are vulnerable, as the flaw exists in any kernel prior to the patch commits referenced in the provided Git URLs. The vulnerability is present across distributions that ship those kernels. The asset is the kernel itself, making the entire host system potentially affected.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low probability of exploitation in the wild. The flaw is not publicly exploitable remotely and would require an attacker with sufficient privileges to trigger a registration failure—such as an administrator loading a kernel module or otherwise forcing a cryptographic registration error—to trigger the denial‑of‑service event. Without such privilege, the risk to a typical user is negligible.
OpenCVE Enrichment
Debian DLA
Debian DSA