mac802154: llsec: reject frames shorter than the authentication tag
Summary
| CVE | CVE-2026-68125 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-10 13:19:57 UTC |
| Updated | 2026-08-10 13:19:57 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
mac802154: llsec: reject frames shorter than the authentication tag
llsec_do_decrypt_auth() computes the associated-data length for the
AEAD request as
assoclen += datalen - authlen;
where datalen is the number of bytes after the MAC header and authlen
(4, 8 or 16) is the length of the authentication tag. Nothing verifies
that the frame actually carries at least authlen payload bytes. A
secured frame whose payload is shorter than the tag makes
datalen - authlen negative; assoclen is then passed to
aead_request_set_ad() as an unsigned value close to 4 GiB, so
crypto_aead_decrypt() walks far off the end of the scatterlist that
only spans the real frame.
The frame is fully attacker-controlled and reaches this path from any
IEEE 802.15.4 peer in radio range. Reject frames whose payload is
shorter than the authentication tag before the subtraction.
Dynamically reproduced on a KASAN kernel as a general-protection-fault
in the AEAD scatterwalk, and the fix confirmed. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 4c14a2fb5d143e4ed94143be2b8c1961b47df9af 5bbf0cd9b6a7076af86c75e87e180099be2e11ae git |
Not specified |
| CNA |
Linux |
Linux |
affected 4c14a2fb5d143e4ed94143be2b8c1961b47df9af de80808f37d99c6dc67bb6f97eea00c8f57a8821 git |
Not specified |
| CNA |
Linux |
Linux |
affected 4c14a2fb5d143e4ed94143be2b8c1961b47df9af f20dedce0429b293d4bad604e0d3f65d8ac96c83 git |
Not specified |
| CNA |
Linux |
Linux |
affected 4c14a2fb5d143e4ed94143be2b8c1961b47df9af e09e0301d616c1ef38a5e64e8e4326fd39df13cc git |
Not specified |
| CNA |
Linux |
Linux |
affected 4c14a2fb5d143e4ed94143be2b8c1961b47df9af fd3a3f28ed60c6af4b2a39933b151d6b27842c3b git |
Not specified |
| CNA |
Linux |
Linux |
affected 3.16 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 3.16 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.6.148 6.6.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.101 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.42 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.6 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc5 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/e09e0301d616c1ef38a5e64e8e4326fd39df13cc |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/de80808f37d99c6dc67bb6f97eea00c8f57a8821 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/f20dedce0429b293d4bad604e0d3f65d8ac96c83 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/fd3a3f28ed60c6af4b2a39933b151d6b27842c3b |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/5bbf0cd9b6a7076af86c75e87e180099be2e11ae |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.