← All Advisories

CVE-2026-80836

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-80836

Key Details

CVECVE-2026-80836
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

crypto: virtio - bound the akcipher result length

virtio_crypto_dataq_akcipher_callback() sets the result length from the

device-reported response length without bounding it to the destination

buffer, which was allocated for the original request length.

sg_copy_from_buffer() then reads that many bytes from the destination

buffer; a backend reporting a larger length over-reads adjacent kernel

heap into the caller's scatterlist (an out-of-bounds read).

Clamp the reported length to the originally requested destination length.

A conforming device reports no more than that, so valid results are

unaffected. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-80836
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-80836