{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-80565","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-08-26T14:34:25.767Z","datePublished":"2026-08-26T14:37:28.953Z","dateUpdated":"2026-08-27T05:01:50.972Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-27T05:01:50.972Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qce - fix error path in devm_qce_register_algs\n\nIf ops->register_algs() fails, the error path repeatedly calls the same\nops->unregister_algs() from the failed registration. Use the loop index\nto unregister the previously registered algorithms instead."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:L - The flaw is in devm_qce_register_algs() called only from qce_crypto_probe() during platform-driver initialization at boot or qcrypto module load, not from any network, ioctl, or AF_ALG userspace path.\nAC:L - On modular builds an attacker can reload qcrypto under memory pressure to force register_algs() failure, and once algorithms leak the UAF is reliably triggered by normal kernel crypto consumers such as fscrypt selecting high-priority QCE transforms.\nPR:L - After the flawed probe error path leaves QCE algorithms registered, unprivileged local processes on Qualcomm phones and embedded targets reach them through routine fscrypt/dm-crypt kernel crypto without capabilities or init-namespace root.\nUI:N - Exploitation requires no victim interaction beyond ordinary encrypted filesystem or storage activity that automatically exercises kernel crypto after the probe failure has occurred.\nS:U - Impact is confined to kernel memory corruption and privilege escalation within the same kernel security domain, not a VM, IOMMU, or sandbox boundary crossing.\nC:H - Leaked algorithm templates retain tmpl->qce pointers to the devm-freed qce_device, creating a kernel heap use-after-free that can be leveraged for arbitrary kernel memory disclosure.\nI:H - The dangling qce_device UAF corrupts kernel heap objects and control fields (mutex, DMA, MMIO pointers) reachable from crypto request handlers, enabling arbitrary write and potential code execution.\nA:H - Dereferencing the freed qce_device during QCE crypto operations can cause kernel oops, panic, or hang, and UAF corruption inherently threatens system availability."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/crypto/qce/core.c"],"versions":[{"version":"9e403fea74ecbe6b4a4321f13bd4bc929382908d","lessThan":"dbca8b798caf47fb2799a26dd09c9ad66305883d","status":"affected","versionType":"git"},{"version":"f52f00efd8c0088992ac07ef46af6096e4f0e52e","lessThan":"fef187c6194d67395182d58169dd14ba631f1b41","status":"affected","versionType":"git"},{"version":"5d5b673b4dd260226b2202f66a920566c27051f3","lessThan":"1ece8e16c085e8cd60ecbdb641269aaa53d31da4","status":"affected","versionType":"git"},{"version":"e914b2f795b6995bb0e7db45caa4a912dca09e65","lessThan":"de52c713d21806b93b00a6074056b57aec4f8919","status":"affected","versionType":"git"},{"version":"76e6d50fa5a2fb466edcc8b513d7aad372312c2a","lessThan":"c7dc487aade12c692add3221673c9bdf32dc24f5","status":"affected","versionType":"git"},{"version":"e80cf84b608725303113d6fe98bb727bf7b7a40d","lessThan":"a134e4b8102c077286818ee112b9f925db613d4c","status":"affected","versionType":"git"},{"version":"e80cf84b608725303113d6fe98bb727bf7b7a40d","lessThan":"4e88b4fda48282f3fd504b4d4f5d2d4f996b76ce","status":"affected","versionType":"git"},{"version":"e80cf84b608725303113d6fe98bb727bf7b7a40d","lessThan":"9c75402286409f5e1a75e4a445555c84066f89db","status":"affected","versionType":"git"},{"version":"8c735ef894dfcca8d0a1cc554f83a82a70fd5b76","status":"affected","versionType":"git"},{"version":"4007883dc7df1dbaeb461b850e0b1b27c057affc","status":"affected","versionType":"git"},{"version":"5.10.235","lessThan":"5.10.266","status":"affected","versionType":"semver"},{"version":"5.15.179","lessThan":"5.15.217","status":"affected","versionType":"semver"},{"version":"6.1.129","lessThan":"6.1.184","status":"affected","versionType":"semver"},{"version":"6.6.78","lessThan":"6.6.153","status":"affected","versionType":"semver"},{"version":"6.12.14","lessThan":"6.12.105","status":"affected","versionType":"semver"},{"version":"5.4.291","lessThan":"5.5","status":"affected","versionType":"semver"},{"version":"6.13.3","lessThan":"6.14","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/crypto/qce/core.c"],"versions":[{"version":"6.14","status":"affected"},{"version":"0","lessThan":"6.14","status":"unaffected","versionType":"semver"},{"version":"5.10.266","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.217","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.184","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.153","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.105","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.46","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.10","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.235","versionEndExcluding":"5.10.266"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.179","versionEndExcluding":"5.15.217"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.129","versionEndExcluding":"6.1.184"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.78","versionEndExcluding":"6.6.153"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12.14","versionEndExcluding":"6.12.105"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.14","versionEndExcluding":"6.18.46"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.14","versionEndExcluding":"7.1.10"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.14","versionEndExcluding":"7.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.4.291"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.13.3"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/dbca8b798caf47fb2799a26dd09c9ad66305883d"},{"url":"https://git.kernel.org/stable/c/fef187c6194d67395182d58169dd14ba631f1b41"},{"url":"https://git.kernel.org/stable/c/1ece8e16c085e8cd60ecbdb641269aaa53d31da4"},{"url":"https://git.kernel.org/stable/c/de52c713d21806b93b00a6074056b57aec4f8919"},{"url":"https://git.kernel.org/stable/c/c7dc487aade12c692add3221673c9bdf32dc24f5"},{"url":"https://git.kernel.org/stable/c/a134e4b8102c077286818ee112b9f925db613d4c"},{"url":"https://git.kernel.org/stable/c/4e88b4fda48282f3fd504b4d4f5d2d4f996b76ce"},{"url":"https://git.kernel.org/stable/c/9c75402286409f5e1a75e4a445555c84066f89db"}],"title":"crypto: qce - fix error path in devm_qce_register_algs","x_generator":{"engine":"bippy-1.2.0"}}}}