{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2022-49260",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2025-02-26T01:49:39.296Z",
        "datePublished": "2025-02-26T01:56:12.548Z",
        "dateUpdated": "2026-08-05T08:54:28.487Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-05T08:54:28.487Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: hisilicon/sec - fix the aead software fallback for engine\n\nDue to the subreq pointer misuse the private context memory. The aead\nsoft crypto occasionally casues the OS panic as setting the 64K page.\nHere is fix it."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:N - On Kunpeng920 systems, hisi_sec GCM is selected as the rfc4106(gcm(aes)) child for IPsec ESP; inbound ESP decrypt with short elen (1–8) yields child cryptlen <= authsize and hits the buggy soft-fallback path while processing attacker-controlled network packets.\nAC:L - The attacker fully controls ESP packet length (or AF_ALG cryptlen) and can reliably force the zero/short-length fallback; no race or external precondition beyond the presence of the affected accelerator is required.\nPR:N - ESP decrypt runs on SPI-matched packets before GCM tag authentication succeeds, so an unauthenticated remote peer can trigger the soft-fallback memory corruption; no local account or capability is required in the IPsec scenario.\nUI:N - Exploitation requires only attacker-sent ESP packets (or the attacker’s own AF_ALG operations); no separate victim action is needed.\nS:U - Impact is kernel heap corruption and potential privilege escalation within the same host OS authority, not a VM/IOMMU/sandbox boundary escape.\nC:H - The bug treats undersized sec_req private context as a full aead_request plus software-GCM reqctx, causing a heap out-of-bounds write/type confusion that can be leveraged for arbitrary kernel memory disclosure.\nI:H - The same out-of-bounds write into adjacent heap objects provides a kernel memory corruption primitive usable for integrity compromise and control-flow hijacking.\nA:H - The commit documents OS panic on the affected 64K-page configuration, and heap corruption from the oversized soft-crypto request context can oops/panic the kernel."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/crypto/hisilicon/sec2/sec_crypto.c"
                    ],
                    "versions": [
                        {
                            "version": "6c46a3297beae4ae2d22b26da5e091f058381c7c",
                            "lessThan": "40dba7c26e897c637e91312b35f664f1d4d0073c",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "6c46a3297beae4ae2d22b26da5e091f058381c7c",
                            "lessThan": "ef7b10f3cac7810ddcfd976304fd125aca33d144",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "6c46a3297beae4ae2d22b26da5e091f058381c7c",
                            "lessThan": "5c1149e2abe0b7489300736b8277b45b113de67f",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "6c46a3297beae4ae2d22b26da5e091f058381c7c",
                            "lessThan": "0a2a464f863187f97e96ebc6384c052cafd4a54c",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/crypto/hisilicon/sec2/sec_crypto.c"
                    ],
                    "versions": [
                        {
                            "version": "5.14",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "5.14",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.33",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.16.19",
                            "lessThanOrEqual": "5.16.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.17.2",
                            "lessThanOrEqual": "5.17.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.18",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.14",
                                    "versionEndExcluding": "5.15.33"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.14",
                                    "versionEndExcluding": "5.16.19"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.14",
                                    "versionEndExcluding": "5.17.2"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.14",
                                    "versionEndExcluding": "5.18"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/40dba7c26e897c637e91312b35f664f1d4d0073c"
                },
                {
                    "url": "https://git.kernel.org/stable/c/ef7b10f3cac7810ddcfd976304fd125aca33d144"
                },
                {
                    "url": "https://git.kernel.org/stable/c/5c1149e2abe0b7489300736b8277b45b113de67f"
                },
                {
                    "url": "https://git.kernel.org/stable/c/0a2a464f863187f97e96ebc6384c052cafd4a54c"
                }
            ],
            "title": "crypto: hisilicon/sec - fix the aead software fallback for engine",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}