Home

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: essiv - Check ssize for decryption and in-place encryption Move the ssize check to the start in essiv_aead_crypt so that it's also checked for decryption and in-place encryption.

PUBLISHED Reserved 2025-04-16 | Published 2025-10-24 | Updated 2025-10-29 | Assigner Linux

Product status

Default status
unaffected

be1eb7f78aa8fbe34779c56c266ccd0364604e71 (git) before 29294dd6f1e7acf527255fb136ffde6602c3a129
affected

be1eb7f78aa8fbe34779c56c266ccd0364604e71 (git) before 71f03f8f72d9c70ffba76980e78b38c180e61589
affected

be1eb7f78aa8fbe34779c56c266ccd0364604e71 (git) before df58651968f82344a0ed2afdafd20ecfc55ff548
affected

be1eb7f78aa8fbe34779c56c266ccd0364604e71 (git) before 248ff2797ff52a8cbf86507f9583437443bf7685
affected

be1eb7f78aa8fbe34779c56c266ccd0364604e71 (git) before f37e7860dc5e94c70b4a3e38a5809181310ea9ac
affected

be1eb7f78aa8fbe34779c56c266ccd0364604e71 (git) before dc4c854a5e7453c465fa73b153eba4ef2a240abe
affected

be1eb7f78aa8fbe34779c56c266ccd0364604e71 (git) before da7afb01ba05577ba3629f7f4824205550644986
affected

be1eb7f78aa8fbe34779c56c266ccd0364604e71 (git) before 6bb73db6948c2de23e407fe1b7ef94bf02b7529f
affected

Default status
affected

5.4
affected

Any version before 5.4
unaffected

5.4.301 (semver)
unaffected

5.10.246 (semver)
unaffected

5.15.195 (semver)
unaffected

6.1.157 (semver)
unaffected

6.6.113 (semver)
unaffected

6.12.54 (semver)
unaffected

6.17.4 (semver)
unaffected

6.18-rc1 (original_commit_for_fix)
unaffected

References

git.kernel.org/...c/29294dd6f1e7acf527255fb136ffde6602c3a129

git.kernel.org/...c/71f03f8f72d9c70ffba76980e78b38c180e61589

git.kernel.org/...c/df58651968f82344a0ed2afdafd20ecfc55ff548

git.kernel.org/...c/248ff2797ff52a8cbf86507f9583437443bf7685

git.kernel.org/...c/f37e7860dc5e94c70b4a3e38a5809181310ea9ac

git.kernel.org/...c/dc4c854a5e7453c465fa73b153eba4ef2a240abe

git.kernel.org/...c/da7afb01ba05577ba3629f7f4824205550644986

git.kernel.org/...c/6bb73db6948c2de23e407fe1b7ef94bf02b7529f

cve.org (CVE-2025-40019)

nvd.nist.gov (CVE-2025-40019)

Download JSON