CVE-2026-23060: crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec
In the Linux kernel, the following vulnerability has been resolved:
crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec
authencesn assumes an ESP/ESN-formatted AAD. When assoclen is shorter than the minimum expected length, cryptoauthencesndecrypt() can advance past the end of the destination scatterlist and trigger a NULL pointer dereference in scatterwalkmapandcopy(), leading to a kernel panic (DoS).
Add a minimum AAD length check to fail fast on invalid inputs.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.251-4Fixed in 6.1.170-3Fixed in 6.12.73-1Fixed in 6.12.86-1Fixed in 7.0.4-1 - Upgrade
Upgrade
debian/linux-6.1to a version that resolves this vulnerability.Fixed in 6.1.170-3~deb11u1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23060?
CVE-2026-23060 has a medium severity rating of 5.5 on the CVSS scale.
How do I fix CVE-2026-23060?
To fix CVE-2026-23060, you should apply the available patches provided for the Linux kernel.
What risk level is associated with CVE-2026-23060?
CVE-2026-23060 has a risk level of 24, indicating it poses a moderate threat.
What is the nature of the vulnerability in CVE-2026-23060?
CVE-2026-23060 involves a null pointer dereference in the Linux kernel caused by processing too-short AAD.
Which software is affected by CVE-2026-23060?
CVE-2026-23060 affects the Linux kernel, specifically versions associated with Debian and Linux 6.1.