CVE-2026-63805: crypto: nx - fix nx_crypto_ctx_exit argument

Published Jul 19, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

crypto: nx - fix nxcryptoctxexit argument

nxcryptoctxshashexit calls nxcryptoctxexit with cryptoshashctx(...) but cryptoshashctx gives a nxcryptoctx , not a cryptotfm .

Fix the type in nxcryptoctxexit and drop the bogus cryptotfmctx call.

This fixes the following oops:

BUG: Unable to handle kernel data access at 0xc0403effffffffc8 Faulting instruction address: 0xc000000000396cb4 Oops: Kernel access of bad area, sig: 11 [#15] Call Trace: nxcryptoctxshashexit+0x24/0x60 cryptoshashexittfm+0x28/0x40 cryptodestroytfm+0x98/0x140 cryptoexitahashusingshash+0x20/0x40 cryptodestroytfm+0x98/0x140 hashrelease+0x1c/0x30 algsockdestruct+0x38/0x60 skdestruct+0x48/0x2b0 afalgrelease+0x58/0xb0 sockrelease+0x68/0x150 sockclose+0x20/0x40 fput+0x110/0x3a0 sysclose+0x48/0xa0 systemcallexception+0x140/0x2d0 systemcallcommon+0xf4/0x258

.. which came from hardlink(1) opportunistically using AFALG.

The same problem exists with nxcryptoctxskcipherexit getting a context it wasn't expecting, but apparently nobody hit that for years.

Affected Software

3 affected components
Linux Linux kernel
Linux Linux kernel>=5.5<6.18.38
Linux Linux kernel>=6.19<7.1.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    If possible, avoid using AF_ALG (e.g., the hardlink opportunistic use noted in the incident) until the kernel fix is applied.

Event History

Jul 19, 2026
CVE Published
via MITRE·12:02 PM
Data Sourced
via MITRE·12:02 PM
DescriptionSeverity
Data Sourced
via NVD·12:16 PM
RemedyDescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-63805?

The severity of CVE-2026-63805 is high with a CVSS score of 7.8.

2

How do I fix CVE-2026-63805?

To fix CVE-2026-63805, apply the available patch provided in the upstream Linux kernel releases.

3

What are the potential impacts of CVE-2026-63805?

CVE-2026-63805 may lead to vulnerabilities in cryptographic processes, potentially compromising data integrity and confidentiality.

4

Which software is affected by CVE-2026-63805?

CVE-2026-63805 affects the Linux kernel.

5

When was CVE-2026-63805 reported?

CVE-2026-63805 was published on July 19, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203