{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-53055","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-06-09T07:44:35.381Z","datePublished":"2026-06-24T16:30:00.876Z","dateUpdated":"2026-08-05T12:32:59.383Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:32:59.383Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: hisilicon/sec2 - prevent req used-after-free for sec\n\nDuring packet transmission, if the system is under heavy load,\nthe hardware might complete processing the packet and free the\nrequest memory (req) before the transmission function finishes.\nIf the software subsequently accesses this req, a use-after-free\nerror will occur. The qp_ctx memory exists throughout the packet\nsending process, so replace the req with the qp_ctx."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL"},"scenarios":[{"lang":"en","value":"AV:N - In the highest reasonable deployment, SEC2 is selected as the async AEAD provider for in-kernel network crypto such as kTLS AES-GCM/CCM, where remote TLS records reach `crypto_aead_decrypt()` and then the vulnerable SEC2 send path. AF_ALG also provides a local path, but the network-triggered kTLS/ESP-style path is the higher defensible attack vector.\nAC:L - The bug is a request use-after-free after hardware submission, and an attacker can drive many asynchronous crypto requests by sending repeated records/packets to create the completion-before-return window. No special condition outside attacker-influenced load and request timing is required for triggering.\nPR:N - A remote client can reach the vulnerable crypto operation through a network service using kTLS without any local account or kernel capability. The attacker only needs to establish/send traffic to the service, not authenticate to the host as a privileged user.\nUI:N - No victim user action is required once the vulnerable kernel and service configuration are present. The attacker triggers processing by sending network traffic.\nS:U - The vulnerable component and impacted resources are within the same kernel security authority. This is not a VM escape, IOMMU bypass, or other cross-scope boundary violation.\nC:H - The flaw is a use-after-free of a crypto request object, and reclaimed object contents can influence stale pointer dereferences. Under the required conservative scoring rule, this supports potential kernel memory disclosure or broader exploitation.\nI:H - The stale `req->ctx->sec` pointer chain is used for an atomic counter update after free, giving a plausible memory corruption/write primitive if the freed request is reclaimed. As a UAF in kernel heap memory, it is scored as high integrity impact.\nA:H - Even without full exploitation, dereferencing freed request memory can cause kernel oops, panic, or service-disrupting memory corruption. The trigger can be repeated with continued traffic."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/crypto/hisilicon/sec2/sec_crypto.c"],"versions":[{"version":"f0ae287c50455f7be0d8dd45a803d403c7aa4d2e","lessThan":"b375c3c7209cc59e40e97998aa9bc768369cca0e","status":"affected","versionType":"git"},{"version":"f0ae287c50455f7be0d8dd45a803d403c7aa4d2e","lessThan":"ad73563f3a1edbfddf2724136c6a15826b354e18","status":"affected","versionType":"git"},{"version":"f0ae287c50455f7be0d8dd45a803d403c7aa4d2e","lessThan":"67b53a660e6bf0da2fa8d8872e897a14d8059eaf","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/crypto/hisilicon/sec2/sec_crypto.c"],"versions":[{"version":"6.17","status":"affected"},{"version":"0","lessThan":"6.17","status":"unaffected","versionType":"semver"},{"version":"6.18.33","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.10","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"6.18.33"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"7.0.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/b375c3c7209cc59e40e97998aa9bc768369cca0e"},{"url":"https://git.kernel.org/stable/c/ad73563f3a1edbfddf2724136c6a15826b354e18"},{"url":"https://git.kernel.org/stable/c/67b53a660e6bf0da2fa8d8872e897a14d8059eaf"}],"title":"crypto: hisilicon/sec2 - prevent req used-after-free for sec","x_generator":{"engine":"bippy-1.2.0"}}}}