Review reviewHigh

CVE-2026-53016

Linux Linux, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - copy IV using skcipher ivsize AF_ALG rfc3686-ctr-aes-ccp requests pass an 8-byte IV to the driver. ccp_aes_complete() restores AES_BLOCK_SIZE bytes into the caller's IV buffer while RFC3686 skciphers expose an 8-byte IV, so the restore overruns the provided buffer. Use crypto_skcipher_ivsize() to copy only the algorithm's IV length.

CVSS
7.8
EPSS
0.14%
3.84% percentile
CISA KEV
Not listed
Published
2026.06.25
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.14%
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - copy IV using skcipher ivsize AF_ALG rfc3686-ctr-aes-ccp requests pass an 8-byte IV to the driver. ccp_aes_complete() restores AES_BLOCK_SIZE bytes into the caller's IV buffer while RFC3686 skciphers expose an 8-byte IV, so the restore overruns the provided buffer. Use crypto_skcipher_ivsize() to copy only the algorithm's IV length.

Affected product and versions

Product
Linux Linux, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9
Affected versions
>= 2b789435d7f36ed918d92db647f3a2f3fec9bb1f < 939061b2d0f7f15114e34b4ce878ef50ff4089c3, >= 2b789435d7f36ed918d92db647f3a2f3fec9bb1f < 798d409a8949f3f495f238549b86de2886b129bd, >= 2b789435d7f36ed918d92db647f3a2f3fec9bb1f < dfb2cf434829819268fe50f41542aad318ad62b2, >= 2b789435d7f36ed918d92db647f3a2f3fec9bb1f < eecee15e263ccb8cd77170a56ab6c969cb54dd6a, >= 2b789435d7f36ed918d92db647f3a2f3fec9bb1f < bb01d8f1f385bc9034ca114d3508c7fdea24fc9a, >= 2b789435d7f36ed918d92db647f3a2f3fec9bb1f < df9784bb5b637ac80f4a2768a58ca9a50bef28a9, >= 2b789435d7f36ed918d92db647f3a2f3fec9bb1f < 227c1e1d9e2aa4cfc65ba446d5690da1f546cda4, >= 2b789435d7f36ed918d92db647f3a2f3fec9bb1f < a7a1f3cdd64d8a165d9b8c9e9ad7fb46ac19dfc4, >= 3.14, >= 3.14 < 5.10.258, >= 5.11 < 5.15.209, >= 5.16 < 6.1.175, >= 6.2 < 6.6.141, >= 6.7 < 6.12.91, >= 6.13 < 6.18.33, >= 6.19 < 7.0.10
Fixed versions
5.10.258, 5.15.209, 6.1.175, 6.6.141, 6.12.91, 6.18.33, 7.0.10

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux Linux, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9 and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-787, CWE-805
CVE-2026-53016 — Linux Linux, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 9 | SECUFOCUS NOW