{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-39789","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2025-04-16T07:20:57.131Z","datePublished":"2025-09-11T16:56:37.912Z","dateUpdated":"2026-08-05T12:05:09.715Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:05:09.715Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: x86/aegis - Add missing error checks\n\nThe skcipher_walk functions can allocate memory and can fail, so\nchecking for errors is necessary."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","baseScore":7.3,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The AEGIS-128 AEAD is driven from the local crypto API — an unprivileged user reaches it directly via an AF_ALG/algif_aead socket, and in-kernel consumers (dm-crypt, xfrm ESP) are configured locally. A remote peer cannot itself supply input that reaches the failing allocation, so this is local.\nAC:L - The failure requires a memory allocation failure inside skcipher_walk, but the attacker can both force the allocating slow path on every walk step (by submitting scatterlists fragmented below the 16-byte chunksize) and induce the memory pressure, then retry the operation arbitrarily many times; the GFP_ATOMIC variant used by softirq consumers fails readily under attacker-generated load.\nPR:L - Binding an AF_ALG socket to \"aegis128\" and issuing encrypt requests requires only an unprivileged local account — no capability, and module autoload happens on the user's behalf.\nUI:N - The attacker triggers the encrypt/decrypt path entirely on their own; no victim action is needed.\nS:U - The faulty error handling and its consequences stay within the kernel's own security authority; no VM, IOMMU, or sandbox boundary is crossed.\nC:H - On the unchecked error path the encrypt call returns success without encrypting, so the \"ciphertext\" handed to the caller is the raw plaintext (in-place operations) or stale kernel buffer contents (out-of-place, e.g. dm-crypt/ESP buffers), disclosing data that was supposed to be protected to disk, network peers, or backups.\nI:H - The kernel reports a successful AEAD operation while producing unencrypted, partially encrypted, or stale output with a mismatched tag, so data written to encrypted storage or an encrypted tunnel is silently wrong and cannot be distinguished from valid output by the caller.\nA:L - No kernel crash, hang, or corruption occurs; the impact is that the silently bad ciphertext/tag causes downstream rejection — dropped IPsec packets, I/O errors on integrity-protected volumes, and unrecoverable stored blocks — which is a limited interruption rather than a full loss of availability."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/x86/crypto/aegis128-aesni-glue.c"],"versions":[{"version":"1d373d4e8e15b358f08de52956b32e0e38a11f84","lessThan":"475104178f4d30e749ee4f5473c87f692b93bebb","status":"affected","versionType":"git"},{"version":"1d373d4e8e15b358f08de52956b32e0e38a11f84","lessThan":"3d9eb180fbe8828cce43bce4c370124685b205c3","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["arch/x86/crypto/aegis128-aesni-glue.c"],"versions":[{"version":"4.18","status":"affected"},{"version":"0","lessThan":"4.18","status":"unaffected","versionType":"semver"},{"version":"6.16.4","lessThanOrEqual":"6.16.*","status":"unaffected","versionType":"semver"},{"version":"6.17","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"6.16.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"4.18","versionEndExcluding":"6.17"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/475104178f4d30e749ee4f5473c87f692b93bebb"},{"url":"https://git.kernel.org/stable/c/3d9eb180fbe8828cce43bce4c370124685b205c3"}],"title":"crypto: x86/aegis - Add missing error checks","x_generator":{"engine":"bippy-1.2.0"}}}}