CVE-2026-74578
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
16/08/2026
Última modificación:
16/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
crypto: algif_skcipher - force synchronous processing on trees without ctx->state<br />
<br />
The AIO/async path in skcipher_recvmsg() passes the socket-wide ctx->iv<br />
directly into the skcipher request. After io_submit() the socket lock is<br />
dropped and the request is processed asynchronously, so a concurrent<br />
sendmsg(ALG_SET_IV) can overwrite ctx->iv and make the in-flight request<br />
run under an attacker-controlled IV. For CTR/stream modes this is<br />
IV/keystream reuse and lets an unprivileged user recover the plaintext of<br />
a concurrent operation.<br />
<br />
Snapshotting ctx->iv into per-request storage for the async path is not<br />
sufficient. For ciphers with statesize == 0 - which includes cbc and ctr -<br />
the MSG_MORE inter-chunk IV chaining is carried solely by the in-place<br />
req->iv writeback, which a snapshot redirects into per-request memory that<br />
af_alg_free_resources() releases on completion, silently producing wrong<br />
output. Writing the IV back from the completion callback instead is not<br />
possible either: that would require lock_sock() there, but the callback can<br />
run in softirq/atomic context, so it must not sleep.<br />
<br />
Make the operation synchronous instead, which removes both the IV race and<br />
any writeback race. This is equivalent to the upstream resolution, commit<br />
fcc77d33a34c ("net: Remove support for AIO on sockets"), which removed the<br />
AIO socket path across net/ entirely and so produces the same end state for<br />
this file. This patch deviates from that commit deliberately: rather than<br />
removing AIO socket support tree-wide, which would be far too invasive for<br />
stable, it removes only the AIO branch in crypto/algif_skcipher.c.<br />
io_submit() now completes synchronously; AF_ALG async is rarely used in<br />
practice.<br />
<br />
The -EIOCBQUEUED check in skcipher_recvmsg() is now dead but harmless,<br />
and is left alone to keep the fix minimal.<br />
<br />
Tested on 6.6.y: attacker IV injection dropped from 2296/200000 to 0/200000<br />
after the change; MSG_MORE chunked CTR output bit-identical to single-shot.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/60eafc7b08c6689ea3ad39eff8d97aefc8a087c7
- https://git.kernel.org/stable/c/73dd3bf704ca6c20639de70c08e9a10bee904a95
- https://git.kernel.org/stable/c/7b91e51d0eb7cbb07f7f086f9176bd93dbbc85dd
- https://git.kernel.org/stable/c/b05defc41b27c7d0c05c45f67bf5b91c28f93669
- https://git.kernel.org/stable/c/bf09b0be8e851f050e98da702d247c14d81b591a
- https://git.kernel.org/stable/c/d7860b682da55433b5da0591b0e4c1982ecd2689
- https://git.kernel.org/stable/c/f1a87ca0843d74482402a206ea2dfb315ee9acbd
- https://git.kernel.org/stable/c/fcc77d33a34cf271702e8daafb6c593e4626776d



