CVE-2026-46028: crypto: algif_aead - snapshot IV for async AEAD requests
Published May 27, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
Affected Software
9 affected componentsFixes available
Linux Linux kernel
Linux Linux kernel>=4.14<5.10.254
Linux Linux kernel>=5.11<5.15.204
Linux Linux kernel>=5.16<6.1.170
Linux Linux kernel>=6.2<6.6.137
Linux Linux kernel>=6.7<6.12.85
Linux Linux kernel>=6.13<6.18.27
Linux Linux kernel>=6.19<7.0.4
debian/linux<=5.10.223-1
5.10.257-16.1.170-36.1.174-16.12.86-16.12.94-17.0.12-27.0.13-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.257-1Fixed in 6.1.170-3Fixed in 6.1.174-1Fixed in 6.12.86-1Fixed in 6.12.94-1Fixed in 7.0.12-2Fixed in 7.0.13-1
Event History
May 27, 2026
CVE Published
via MITRE·12:56 PM
Data Sourced
via MITRE·12:56 PM
Description
Data Sourced
via NVD·02:17 PM
RemedyDescriptionSeverityAffected Software
Jun 1, 2026
Data Sourced
via Launchpad·01:31 PM
Description
Jun 21, 2026
Data Sourced
via Debian·10:27 PM
DescriptionAffected Software
Jun 25, 2026
Data Sourced
via Ubuntu·10:29 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-46028?
The severity of CVE-2026-46028 is assessed as medium with a CVSS score of 5.5.
2
How do I fix CVE-2026-46028?
To fix CVE-2026-46028, update the Linux kernel to a version that includes the security patch addressing this vulnerability.
3
What systems are affected by CVE-2026-46028?
CVE-2026-46028 affects systems running specific versions of the Linux kernel and Debian Linux.
4
What is the risk associated with CVE-2026-46028?
The risk associated with CVE-2026-46028 includes a potential denial of service due to improper handling of async AEAD requests.
5
When was CVE-2026-46028 published?
CVE-2026-46028 was published on May 27, 2026.