CVE-2026-23060

CVSS

No CVSS.

I

n the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - reject too-short AAD (assoclen<8) to match ESP/ESN spec authencesn assumes an ESP/ESN-formatted AAD. When assoclen is shorter than the minimum expected length, crypto_authenc_esn_decrypt() can advance past the end of the destination scatterlist and trigger a NULL pointer dereference in scatterwalk_map_and_copy(), leading to a kernel panic (DoS). Add a minimum AAD length check to fail fast on invalid inputs.

Configurations

No configuration.

History

06 Feb 2026, 17:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/767e8349f7e929b7dd95c08f0b4cb353459b365e -
  • () https://git.kernel.org/stable/c/df22c9a65e9a9daa368a72fed596af9d7d5876bb -
  • () https://git.kernel.org/stable/c/fee86edf5803f1d1f19e3b4f2dacac241bddfa48 -

04 Feb 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-04 17:16

Updated : 2026-02-06 17:16


NVD link : CVE-2026-23060

Mitre link : CVE-2026-23060

CVE.ORG link : CVE-2026-23060


JSON object : View

Products Affected

No product.

CWE

No CWE.