CVE-2026-53016
In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - copy IV using skcipher ivsize AF_ALG rfc3686-ctr-aes-ccp
CVSS
7.8
Alto
EPSS
0.1%
p4
KEV
—
Exploit Today
1
0-100
Publicado: 24 jun 2026 · Última mod.: 16 sept 2026 · CWE-787 · CWE-805
0.1%EPSS · 30 días0.1%
2026-08-202026-09-17
In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - copy IV using skcipher ivsize AF_ALG rfc3686-ctr-aes-ccp requests pass an 8-byte IV to the driver. ccp_aes_complete() restores AES_BLOCK_SIZE bytes into the caller's IV buffer while RFC3686 skciphers expose an 8-byte IV, so the restore overruns the provided buffer. Use crypto_skcipher_ivsize() to copy only the algorithm's IV length.
- git.kernel.orghttps://git.kernel.org/stable/c/227c1e1d9e2aa4cfc65ba446d5690da1f546cda4
- git.kernel.orghttps://git.kernel.org/stable/c/798d409a8949f3f495f238549b86de2886b129bd
- git.kernel.orghttps://git.kernel.org/stable/c/939061b2d0f7f15114e34b4ce878ef50ff4089c3
- git.kernel.orghttps://git.kernel.org/stable/c/a7a1f3cdd64d8a165d9b8c9e9ad7fb46ac19dfc4
- git.kernel.orghttps://git.kernel.org/stable/c/bb01d8f1f385bc9034ca114d3508c7fdea24fc9a
- git.kernel.orghttps://git.kernel.org/stable/c/df9784bb5b637ac80f4a2768a58ca9a50bef28a9
- git.kernel.orghttps://git.kernel.org/stable/c/dfb2cf434829819268fe50f41542aad318ad62b2
- git.kernel.orghttps://git.kernel.org/stable/c/eecee15e263ccb8cd77170a56ab6c969cb54dd6a
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:38491
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:39494
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:55764
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:55765
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:56574
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:59473
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:59544
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:61256
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:64767
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:65710
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:67721
- access.redhat.comhttps://access.redhat.com/errata/RHSA-2026:67723
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-252807.8 ALT1.5%
——0Memory corruption when processing escape handling flow with insufficient user buffer sizes.1dCVE-2026-240747.8 ALT5.8%
——2Memory Corruption when processing data with large offset and length values exceeds buffer limits during data copy operations.1dCVE-2026-240737.8 ALT5.8%
——2Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.1dCVE-2026-927867.8 ALT2.7%
——1LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to write out-of-bounds memory during SHAP prediction. Attackers can craft malicious model files with invalid node references that trigger out-of-bounds writes at attacker-chosen offsets in the leaf_depth_ buffer during feature contribution computation.2dCVE-2026-202905.8 MED8.9%
——3A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 2 Detection Engine to restart.
This vulnerability is due to incomplete validation of the SSL certificate. An attacker could exploit this vulnerability by sending a crafted SSL connection setup request to be parsed by Snort 2. A successful exploit could allow the attacker to cause the Snort 2 Detection Engine to restart unexpectedly, resulting in a denial of service (DoS) condition.2dCVE-2026-91097—50.4%
——15HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.2d