CVE-2026-80832

Summary

In the Linux kernel, the following vulnerability has been resolved:

crypto: qce - fix CCM AAD buffer underallocation

The AAD buffer allocated in qce_aead_ccm_prepare_buf_assoclen() can be smaller than the length later programmed into the DMA scatterlist.

The allocation size is currently calculated as:

ALIGN(assoclen, 16) + MAX_CCM_ADATA_HEADER_LEN

while the DMA length is set to:

ALIGN(assoclen + adata_header_len, 16)

Since ALIGN() does not distribute over addition, the allocation can be smaller than the DMA length. For example, when assoclen = 32 and adata_header_len = 2:

allocation = ALIGN(32, 16) + 6 = 38 DMA length = ALIGN(32 + 2, 16) = 48

As a result, the QCE hardware can read beyond the allocated buffer while computing the CBC-MAC over the associated data. The extra bytes are folded into the authentication tag, resulting in an incorrect tag and causing CCM self-test failures such as:

alg: aead: ccm-aes-qce encryption test failed (wrong result) on test vector 8

Fix the allocation by adding the maximum possible AAD header length before alignment:

ALIGN(assoclen + MAX_CCM_ADATA_HEADER_LEN, 16)

This guarantees that the allocated buffer is large enough for the fully padded AAD data for all supported header sizes.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux9363efb4181c5e0fbf86bdfa759262aa29f0eb50 < 11775b35ce9f27e73d62188d7d38aa0dc0a219aaaffected
LinuxLinux9363efb4181c5e0fbf86bdfa759262aa29f0eb50 < c9e0f06a023107694698a7930616aeb460d91816affected
LinuxLinux9363efb4181c5e0fbf86bdfa759262aa29f0eb50 < cc56d2b0d77cfeea061e98114992ee687d5eb4ddaffected
LinuxLinux9363efb4181c5e0fbf86bdfa759262aa29f0eb50 < 002f1f99aef7ea631cb687fc17bce64e4963f6aaaffected
LinuxLinux9363efb4181c5e0fbf86bdfa759262aa29f0eb50 < 2f65718b9c1095eef1ae9b374aa0384b1b083f3caffected
LinuxLinux9363efb4181c5e0fbf86bdfa759262aa29f0eb50 < 46a84efe2dbaddde89073a3c00c694486937c34baffected
LinuxLinux9363efb4181c5e0fbf86bdfa759262aa29f0eb50 < 4839f4c21f9c577eedef2919ced878a3057c7fc3affected
LinuxLinux9363efb4181c5e0fbf86bdfa759262aa29f0eb50 < 7f2345f47dd189625f657cd72437179ab4170ee1affected
LinuxLinux5.14affected
LinuxLinux0 < 5.14unaffected
LinuxLinux5.15.220 <= 5.15.*unaffected
LinuxLinux6.1.187 <= 6.1.*unaffected
LinuxLinux6.6.156 <= 6.6.*unaffected
LinuxLinux6.12.108 <= 6.12.*unaffected
LinuxLinux6.18.49 <= 6.18.*unaffected
LinuxLinux7.1.13 <= 7.1.*unaffected
LinuxLinux7.2.3 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References