CVE-2026-28529General(cryptodev-linux / cryptodev-linux)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

cryptodev-linux version 1.14 and prior contain a page reference handling flaw in the get_userbuf function of the /dev/crypto device driver that allows local users to trigger use-after-free conditions. Attackers with access to the /dev/crypto interface can repeatedly decrement reference counts of controlled pages to achieve local privilege escalation.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cryptodev-linux

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • General: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-03-25); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
cryptodev-linux

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-25: 1Mentions · 2026-03-27: 103-2503-27
Signal classification1 categories
General
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • nasm@nasm_re
    General

    It got assigned as CVE-2026-28529: https://www.cve.org/CVERecord?id=CVE-2026-28529

    Post summary

    The post merely announces that CVE-2026-28529 has been assigned and provides a link to the CVE record, with no additional details or context.

    0004094
    756 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-28529 📊 Severity: 8.5 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-28529 #CVE-2026-28529 #CVE #High  #CyberSecurity #InfoSec https://t.co/khhLJ6eMIJ

    Post summary

    The tweet announces a new CVE (CVE‑2026‑28529) with a high severity rating but provides no technical details, exploit references, or remediation information.

    0000028
    123 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcryptodev-linuxcryptodev-linux---

Explore more