Back

HIGH

cryptodev-linux <= 1.14 get_userbuf Use After Free LPE

Published Mar 25, 2026

Description

cryptodev-linux version 1.14 and prior contain a page reference handling flaw in the get_userbuf function of the /dev/crypto device driver that allows local users to trigger use-after-free conditions. Attackers with access to the /dev/crypto interface can repeatedly decrement reference counts of controlled pages to achieve local privilege escalation.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulnCheck
Published Mar 25, 2026
Updated Jul 14, 2026
Reserved Feb 27, 2026

CISA Vulnrichment

Updated Mar 25, 2026

NVD

Status Analyzed
Modified Aug 17, 2026

Red Hat

No data

ENISA EUVD

Assigner VulnCheck
Published Mar 25, 2026
Updated Jul 14, 2026

GitHub

No data