CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption
In the Linux kernel, the following vulnerability has been resolved:
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.257-1Fixed in 6.1.170-3Fixed in 6.1.174-1Fixed in 6.12.86-1Fixed in 6.12.94-1Fixed in 7.0.12-2Fixed in 7.0.13-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.257-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.170-3 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.174-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.86-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.94-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 7.0.12-2 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 7.0.13-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-43077?
CVE-2026-43077 has a medium severity rating of 5.5 according to the CVSS metrics.
What impact does CVE-2026-43077 have on systems?
CVE-2026-43077 can lead to a denial of service condition due to incorrect handling of the minimum receive buffer size.
How do I fix CVE-2026-43077?
The vulnerability can be fixed by applying the available patches for the Linux kernel.
Which software is affected by CVE-2026-43077?
CVE-2026-43077 affects the Linux kernel, specifically distributions like Debian.
When was CVE-2026-43077 published?
CVE-2026-43077 was published on May 6, 2026.