VDB

CVE-2026-80831

CVE-2026-80831 PUBLISHED

Reported by Linux · Published September 4, 2026

In the Linux kernel, the following vulnerability has been resolved: crypto: mxs-dcp - fix source scatterlist length access mxs_dcp_aes_block_crypt() uses sg_dma_len() without mapping the source scatterlist with dma_map_sg() first. Therefore, sg_dma_len() is invalid and could return zero or a stale DMA length, causing encryption and decryption to process the wrong number of bytes when CONFIG_NEED_SG_DMA_LENGTH=y. Use the original scatterlist length instead.

EPSS 0.16% · 6.1th percentile

Risk Scores

EPSS Score
0.16%
6.1th percentile

Affected Products

VendorProductVersions
LinuxLinux15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5, 15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5, 15b59e7c3733f90ff1f7dd66ad77ae1c90bcdff5
LinuxLinux3.14, 0, 5.10.269
LinuxLinux7.3-rc1, 0, 5.10.269
linuxlinux_kernel3.14, 3.14, 3.14

Timeline

  • Sep 4, 2026 Coalition ESS Score
  • Sep 4, 2026 CVE Published
  • Sep 5, 2026 EPSS Score
  • Sep 16, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›