Back

MEDIUM

In do_sss_aes_gcm_256_op of crypto-aes.c, there is a possible out-of-bounds read due to a missing bounds check

Published Sep 15, 2026

Description

In do_sss_aes_gcm_256_op of crypto-aes.c, there is a possible out-of-bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.

Affected products

Remediation

No remediation recorded yet.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Google_Devices
Published Sep 15, 2026
Updated Sep 15, 2026
Reserved Oct 23, 2025
CISA Vulnrichment
Updated Sep 15, 2026
NVD
Status Undergoing Analysis
Modified Sep 16, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Google_Devices
Published Sep 15, 2026
Updated Sep 15, 2026
Exploited since n/a
EUVD-2026-79148