CVE-2026-74578Disclosure

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_skcipher - force synchronous processing on trees without ctx->state The AIO/async path in skcipher_recvmsg() passes the socket-wide ctx->iv directly into the skcipher request. After io_submit() the socket lock is dropped and the request is processed asynchronously, so a concurrent sendmsg(ALG_SET_IV) can overwrite ctx->iv and make the in-flight request run under an attacker-controlled IV. For CTR/stream modes this is IV/keystream reuse and lets an unprivileged user recover the plaintext of a concurrent operation. Snapshotting ctx->iv into per-request storage for the async path is not sufficient. For ciphers with statesize == 0 - which includes cbc and ctr - the MSG_MORE inter-chunk IV chaining is carried solely by the in-place req->iv writeback, which a snapshot redirects into per-request memory that af_alg_free_resources() releases on completion, silently producing wrong output. Writing the IV back from the completion callback instead is not possible either: that would require lock_sock() there, but the callback can run in softirq/atomic context, so it must not sleep. Make the operation synchronous instead, which removes both the IV race and any writeback race. This is equivalent to the upstream resolution, commit fcc77d33a34c ("net: Remove support for AIO on sockets"), which removed the AIO socket path across net/ entirely and so produces the same end state for this file. This patch deviates from that commit deliberately: rather than removing AIO socket support tree-wide, which would be far too invasive for stable, it removes only the AIO branch in crypto/algif_skcipher.c. io_submit() now completes synchronously; AF_ALG async is rarely used in practice. The -EIOCBQUEUED check in skcipher_recvmsg() is now dead but harmless, and is left alone to keep the fix minimal. Tested on 6.6.y: attacker IV injection dropped from 2296/200000 to 0/200000 after the change; MSG_MORE chunked CTR output bit-identical to single-shot.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-08-16); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-16: 2Mentions · 2026-08-17: 1Mentions · 2026-08-26: 1Patch / Workaround · 2026-08-26: 1Technical Details · 2026-08-16: 2Technical Details · 2026-08-17: 1Technical Details · 2026-08-26: 108-1608-1708-26
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-162
Disclosure2
2026-08-171
Disclosure1
2026-08-261
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-74578 In the Linux kernel, the following vulnerability has been resolved: crypto: algif_skcipher - force synchronous processing on trees without ctx->state The AIO/async … https://www.cve.org/CVERecord?id=CVE-2026-74578

    Post summary

    The post announces that CVE‑2026‑74578, a Linux kernel crypto issue, has been fixed, providing a brief technical description but no PoC, exploit code, or active exploitation evidence.

    100011.0K
    58.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-74578 Linux Kernel crypto:algif_skcipher IV Race Condition Allows Plaintext Re... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-74578 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    This tweet is a brief notification linking to a vulnerability report for CVE-2026-74578, a kernel race condition that can leak plaintext, but it lacks details on PoC, exploitation, or mitigation.

    00010156
    4.1K followersView on X
  • Shadowfetch Linux@Shadowfetch
    Disclosure

    On the Linux box, AF_ALG can leak a live CTR IV if you skip the 6.6.145 patch. That is CVE-2026-74578. #Linux #CVE #Kernel

    Post summary

    The post identifies CVE-2026-74578, explaining that AF_ALG can leak a live CTR IV if the 6.6.145 patch is not applied, indicating the patch mitigates the issue but providing no evidence of active exploitation or PoC.

    0000053
    79 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨HIGH - Linux Kernel AF_ALG skcipher IV Race Leads to Keystream Reuse (CVE-2026-74578) In crypto/algif_skcipher.c, the AF_ALG skcipher async recv path races with concurrent sendmsg(ALG_SET_IV), letting a local unprivileged attacker overwrite the socket-wide IV for an in-flight request. In CTR/stream modes this triggers IV/keystream reuse (plus MSG_MORE chaining issues when statesize==0), enabling plaintext recovery and output corruption. 👉Affected: linux kernel (AF_ALG skcipher async receive path)

    Post summary

    The CVE details a race condition in Linux kernel AF_ALG skcipher async receive path that enables an unprivileged local attacker to overwrite the IV, causing keystream reuse and plaintext recovery.

    00000118
    291 followersView on X

Explore more