HIGH
cryptodev-linux <= 1.14 get_userbuf Use After Free LPE
Published Mar 25, 2026
8.5
HIGHCVSS 4.0
EPSS 0.18%
Description
cryptodev-linux version 1.14 and prior contain a page reference handling flaw in the get_userbuf function of the /dev/crypto device driver that allows local users to trigger use-after-free conditions. Attackers with access to the /dev/crypto interface can repeatedly decrement reference counts of controlled pages to achieve local privilege escalation.
Affected products
-
Affected
- ≥ 0, ≤ 1.14
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Cryptodev-Linux | Cryptodev-Linux | unknown | Affected
|
- ≤ 1.14
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-15408 Advisory
- https://gist.github.com/n4sm/0fd2479e0c23e0fa2f192cd8fda45750 exploit
- https://github.com/cryptodev-linux/cryptodev-linux/pull/104 issue-trackingPatchThird Party Advisory
- https://nasm.re/posts/cryptodev-linux-vuln/ technical-descriptionexploitThird Party Advisory
- https://www.vulncheck.com/advisories/cryptodev-linux-get-userbuf-use-after-free-lpe third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-15408 | Advisory | |
| https://gist.github.com/n4sm/0fd2479e0c23e0fa2f192cd8fda45750 | exploit | |
| https://github.com/cryptodev-linux/cryptodev-linux/pull/104 | issue-trackingPatchThird Party Advisory | |
| https://nasm.re/posts/cryptodev-linux-vuln/ | technical-descriptionexploitThird Party Advisory | |
| https://www.vulncheck.com/advisories/cryptodev-linux-get-userbuf-use-after-free-lpe | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Mar 25, 2026
Updated Jul 14, 2026
Reserved Feb 27, 2026
Link CVE-2026-28529
CISA Vulnrichment
Updated Mar 25, 2026
Red Hat
No data
GitHub
No data