CVE-2026-52972

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Cap AEAD AD length to 0x80000000 In order to prevent arithmetic overflows when checking the TX buffer size, cap the associated data length to 0x80000000.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

History

14 Jul 2026, 16:53

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/265ac26d1c5e17b34d497cbda1f754a1ec8552bc - () https://git.kernel.org/stable/c/265ac26d1c5e17b34d497cbda1f754a1ec8552bc - Patch
References () https://git.kernel.org/stable/c/97948906dc8e0ea84775e03e35b60a2063c70193 - () https://git.kernel.org/stable/c/97948906dc8e0ea84775e03e35b60a2063c70193 - Patch
References () https://git.kernel.org/stable/c/a1c5672faf8e93e38c2deac3979cc767ca5cf918 - () https://git.kernel.org/stable/c/a1c5672faf8e93e38c2deac3979cc767ca5cf918 - Patch
References () https://git.kernel.org/stable/c/a4fe4eb580bbc7439f649a496d4cf38415a4021c - () https://git.kernel.org/stable/c/a4fe4eb580bbc7439f649a496d4cf38415a4021c - Patch
References () https://git.kernel.org/stable/c/a9f68d9ed38dd6e5a6c6d75b03d25c1c133e321d - () https://git.kernel.org/stable/c/a9f68d9ed38dd6e5a6c6d75b03d25c1c133e321d - Patch
References () https://git.kernel.org/stable/c/e4c06479d7059888adf2f22bc1ebcf053bf691a2 - () https://git.kernel.org/stable/c/e4c06479d7059888adf2f22bc1ebcf053bf691a2 - Patch
References () https://git.kernel.org/stable/c/e4c4a5074532eaaa14951994a3aad0d479aa7431 - () https://git.kernel.org/stable/c/e4c4a5074532eaaa14951994a3aad0d479aa7431 - Patch
References () https://git.kernel.org/stable/c/f8a5203596797f394ff3f9aa4005597a92249802 - () https://git.kernel.org/stable/c/f8a5203596797f394ff3f9aa4005597a92249802 - Patch
References () https://access.redhat.com/security/cve/CVE-2026-52972 - () https://access.redhat.com/security/cve/CVE-2026-52972 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2492364 - () https://bugzilla.redhat.com/show_bug.cgi?id=2492364 - Issue Tracking, Third Party Advisory
References () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52972.json - () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52972.json - Third Party Advisory
First Time Linux linux Kernel
Linux
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 7.0
v2 : unknown
v3 : 5.5

30 Jun 2026, 03:20

Type Values Removed Values Added
CWE CWE-190
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.0
References
  • () https://access.redhat.com/security/cve/CVE-2026-52972 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2492364 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52972.json -

29 Jun 2026, 06:16

Type Values Removed Values Added
References
  • () https://git.kernel.org/stable/c/e4c06479d7059888adf2f22bc1ebcf053bf691a2 -

24 Jun 2026, 17:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-24 17:17

Updated : 2026-07-15 01:16


NVD link : CVE-2026-52972

Mitre link : CVE-2026-52972

CVE.ORG link : CVE-2026-52972


JSON object : View

Products Affected

linux

  • linux_kernel
CWE
NVD-CWE-noinfo CWE-190

Integer Overflow or Wraparound