cryptodev-linux version 1.14 and prior contain a page reference handling flaw in the get_userbuf function of the /dev/crypto device driver that allows local users to trigger use-after-free conditions. Attackers with access to the /dev/crypto interface can repeatedly decrement reference counts of controlled pages to achieve local privilege escalation.
References
| Link | Resource |
|---|---|
| https://gist.github.com/n4sm/0fd2479e0c23e0fa2f192cd8fda45750 | Exploit |
| https://github.com/cryptodev-linux/cryptodev-linux/pull/104 | Patch Third Party Advisory |
| https://nasm.re/posts/cryptodev-linux-vuln/ | Third Party Advisory |
| https://www.vulncheck.com/advisories/cryptodev-linux-get-userbuf-use-after-free-lpe | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-03-25 14:16
Updated : 2026-08-17 18:02
NVD link : CVE-2026-28529
Mitre link : CVE-2026-28529
CVE.ORG link : CVE-2026-28529
JSON object : View
Products Affected
cryptodev-linux
- cryptodev-linux
CWE
CWE-416
Use After Free
