CVE-2025-39931

crypto: af_alg - Set merge to zero early in af_alg_sendmsg

References

Notes

 carnil> Introduced in 8ff590903d5 ("crypto: algif_skcipher - User-space interface for
 carnil> skcipher operations"). Vulnerable versions: 2.6.38.

Bugs

Status

Branch Status
upstream released (6.17-rc7) [9574b2330dbd2b5459b74d3b5e9619d39299fc6f]
6.18-upstream-stable N/A "Fixed before branching point"
6.17-upstream-stable N/A "Fixed before branching point"
6.16-upstream-stable released (6.16.9) [045ee26aa3920a47ec46d7fcb302420bf01fd753]
6.12-upstream-stable released (6.12.49) [24c1106504c625fabd3b7229611af617b4c27ac7]
6.6-upstream-stable released (6.6.108) [2374c11189ef704a3e4863646369f1b8e6a27d71]
6.1-upstream-stable released (6.1.154) [6241b9e2809b12da9130894cf5beddf088dc1b8a]
5.10-upstream-stable needed
sid released (6.16.9-1)
6.12-trixie-security released (6.12.57-1)
6.1-bookworm-security released (6.1.158-1)
5.10-bullseye-security needed