CVE-2026-52972
crypto: af_alg - Cap AEAD AD length to 0x80000000
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
24 Jun 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In the Linux kernel, the following vulnerability has been resolved:
crypto: af_alg - Cap AEAD AD length to 0x80000000
In order to prevent arithmetic overflows when checking the TX
buffer size, cap the associated data length to 0x80000000.
Affected products
Linux · LinuxWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
https://git.kernel.org/stable/c/265ac26d1c5e17b34d497cbda1f754a1ec8552bchttps://git.kernel.org/stable/c/97948906dc8e0ea84775e03e35b60a2063c70193https://git.kernel.org/stable/c/a1c5672faf8e93e38c2deac3979cc767ca5cf918https://git.kernel.org/stable/c/a4fe4eb580bbc7439f649a496d4cf38415a4021chttps://git.kernel.org/stable/c/a9f68d9ed38dd6e5a6c6d75b03d25c1c133e321dhttps://git.kernel.org/stable/c/e4c4a5074532eaaa14951994a3aad0d479aa7431https://git.kernel.org/stable/c/f8a5203596797f394ff3f9aa4005597a92249802