CVE-2026-32849

NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/opencrypto/cryptodev.c where the local variable iov_len is declared as a signed int but assigned from an unsigned cop->dst_len value, causing undefined behavior when cop->dst_len exceeds INT_MAX. A local attacker with access to /dev/crypto and a compression session type can exploit this vulnerability by providing a dst_len value exceeding INT_MAX to trigger a kernel panic through NULL pointer dereference when CONFIG_SVS is disabled and corrupted UIO pointer arithmetic.
Configurations

No configuration.

History

18 May 2026, 18:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-18 18:17

Updated : 2026-06-17 10:36


NVD link : CVE-2026-32849

Mitre link : CVE-2026-32849

CVE.ORG link : CVE-2026-32849


JSON object : View

Products Affected

No product.

CWE
CWE-190

Integer Overflow or Wraparound

CWE-476

NULL Pointer Dereference