{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-74578",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2026-08-15T05:44:03.917Z",
        "datePublished": "2026-08-16T08:20:32.055Z",
        "dateUpdated": "2026-08-17T05:48:57.219Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-17T05:48:57.219Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: algif_skcipher - force synchronous processing on trees without ctx->state\n\nThe AIO/async path in skcipher_recvmsg() passes the socket-wide ctx->iv\ndirectly into the skcipher request. After io_submit() the socket lock is\ndropped and the request is processed asynchronously, so a concurrent\nsendmsg(ALG_SET_IV) can overwrite ctx->iv and make the in-flight request\nrun under an attacker-controlled IV. For CTR/stream modes this is\nIV/keystream reuse and lets an unprivileged user recover the plaintext of\na concurrent operation.\n\nSnapshotting ctx->iv into per-request storage for the async path is not\nsufficient. For ciphers with statesize == 0 - which includes cbc and ctr -\nthe MSG_MORE inter-chunk IV chaining is carried solely by the in-place\nreq->iv writeback, which a snapshot redirects into per-request memory that\naf_alg_free_resources() releases on completion, silently producing wrong\noutput. Writing the IV back from the completion callback instead is not\npossible either: that would require lock_sock() there, but the callback can\nrun in softirq/atomic context, so it must not sleep.\n\nMake the operation synchronous instead, which removes both the IV race and\nany writeback race. This is equivalent to the upstream resolution, commit\nfcc77d33a34c (\"net: Remove support for AIO on sockets\"), which removed the\nAIO socket path across net/ entirely and so produces the same end state for\nthis file. This patch deviates from that commit deliberately: rather than\nremoving AIO socket support tree-wide, which would be far too invasive for\nstable, it removes only the AIO branch in crypto/algif_skcipher.c.\nio_submit() now completes synchronously; AF_ALG async is rarely used in\npractice.\n\nThe -EIOCBQUEUED check in skcipher_recvmsg() is now dead but harmless,\nand is left alone to keep the fix minimal.\n\nTested on 6.6.y: attacker IV injection dropped from 2296/200000 to 0/200000\nafter the change; MSG_MORE chunked CTR output bit-identical to single-shot."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - Exploitation requires local syscalls on an AF_ALG skcipher socket (socket/bind/accept/sendmsg plus async recvmsg, io_submit, aio_read, or io_uring read); the bug is not reachable from remote network protocols.\nAC:L - The attacker fully controls the race by running concurrent threads or syscalls on the same socket, timing async recvmsg/io_submit against sendmsg(ALG_SET_IV); pre-fix testing achieved thousands of successful IV injections in 200000 attempts.\nPR:L - Any unprivileged local user can create and use AF_ALG skcipher sockets without CAP_NET_ADMIN or init-namespace root; only standard UNIX discretionary access to the target socket FD is required, which includes same-UID multi-threaded processes.\nUI:N - Exploitation is fully attacker-driven through direct syscalls and requires no victim interaction such as opening files, clicking links, or mounting filesystems.\nS:U - Impact is confined to cryptographic operations on the compromised AF_ALG socket within the attacker's security context; it does not cross VM, container, or kernel-user authority boundaries like KVM escape or IOMMU bypass.\nC:H - Concurrent IV injection on CTR/stream ciphers causes keystream reuse, letting an attacker recover the full plaintext of an in-flight decrypt/encrypt on the same keyed socket even when the key never leaves kernel memory.\nI:H - Attacker-controlled IV injection corrupts in-flight cipher output and breaks MSG_MORE CBC/CTR chaining (statesize==0), silently producing attacker-influenced ciphertext/plaintext and undermining cryptographic integrity of concurrent operations.\nA:N - The flaw causes information disclosure and silent cryptographic corruption but does not kernel panic, oops, hang, or reliably deny service; availability impact is none beyond possible application-level misbehavior."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "crypto/algif_skcipher.c"
                    ],
                    "versions": [
                        {
                            "version": "e870456d8e7c8d57c059ea479b5aadbb55ff4c3a",
                            "lessThan": "bf09b0be8e851f050e98da702d247c14d81b591a",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "e870456d8e7c8d57c059ea479b5aadbb55ff4c3a",
                            "lessThan": "73dd3bf704ca6c20639de70c08e9a10bee904a95",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "e870456d8e7c8d57c059ea479b5aadbb55ff4c3a",
                            "lessThan": "f1a87ca0843d74482402a206ea2dfb315ee9acbd",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "e870456d8e7c8d57c059ea479b5aadbb55ff4c3a",
                            "lessThan": "7b91e51d0eb7cbb07f7f086f9176bd93dbbc85dd",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "e870456d8e7c8d57c059ea479b5aadbb55ff4c3a",
                            "lessThan": "60eafc7b08c6689ea3ad39eff8d97aefc8a087c7",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "e870456d8e7c8d57c059ea479b5aadbb55ff4c3a",
                            "lessThan": "d7860b682da55433b5da0591b0e4c1982ecd2689",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "e870456d8e7c8d57c059ea479b5aadbb55ff4c3a",
                            "lessThan": "b05defc41b27c7d0c05c45f67bf5b91c28f93669",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "e870456d8e7c8d57c059ea479b5aadbb55ff4c3a",
                            "lessThan": "fcc77d33a34cf271702e8daafb6c593e4626776d",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "crypto/algif_skcipher.c"
                    ],
                    "versions": [
                        {
                            "version": "4.14",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "4.14",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.261",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.212",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.178",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.145",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.97",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.18.40",
                            "lessThanOrEqual": "6.18.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.1.5",
                            "lessThanOrEqual": "7.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.2",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.14",
                                    "versionEndExcluding": "5.10.261"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.14",
                                    "versionEndExcluding": "5.15.212"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.14",
                                    "versionEndExcluding": "6.1.178"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.14",
                                    "versionEndExcluding": "6.6.145"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.14",
                                    "versionEndExcluding": "6.12.97"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.14",
                                    "versionEndExcluding": "6.18.40"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.14",
                                    "versionEndExcluding": "7.1.5"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.14",
                                    "versionEndExcluding": "7.2"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/bf09b0be8e851f050e98da702d247c14d81b591a"
                },
                {
                    "url": "https://git.kernel.org/stable/c/73dd3bf704ca6c20639de70c08e9a10bee904a95"
                },
                {
                    "url": "https://git.kernel.org/stable/c/f1a87ca0843d74482402a206ea2dfb315ee9acbd"
                },
                {
                    "url": "https://git.kernel.org/stable/c/7b91e51d0eb7cbb07f7f086f9176bd93dbbc85dd"
                },
                {
                    "url": "https://git.kernel.org/stable/c/60eafc7b08c6689ea3ad39eff8d97aefc8a087c7"
                },
                {
                    "url": "https://git.kernel.org/stable/c/d7860b682da55433b5da0591b0e4c1982ecd2689"
                },
                {
                    "url": "https://git.kernel.org/stable/c/b05defc41b27c7d0c05c45f67bf5b91c28f93669"
                },
                {
                    "url": "https://git.kernel.org/stable/c/fcc77d33a34cf271702e8daafb6c593e4626776d"
                }
            ],
            "title": "crypto: algif_skcipher - force synchronous processing on trees without ctx->state",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}