In the Linux kernel, the following vulnerability has been resolved:
crypto: algifhash - fix double free in hashaccept
If accept(2) is called on socket type algifhash with MSGMORE flag set and cryptoahashimport fails, sk2 is freed. However, it is also freed in afalgrelease, leading to slab-use-after-free error.
[
{
"deprecated": false,
"target": {
"file": "crypto/algif_hash.c",
"function": "hash_accept"
},
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0346f4b742345d1c733c977f3a7aef5a6419a967",
"id": "CVE-2025-38079-03c8db14",
"digest": {
"function_hash": "145604721111116349127241263629572711823",
"length": 894.0
}
},
{
"deprecated": false,
"target": {
"file": "crypto/algif_hash.c",
"function": "hash_accept"
},
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2f45a8d64fb4ed4830a4b3273834ecd6ca504896",
"id": "CVE-2025-38079-2834ad36",
"digest": {
"function_hash": "145604721111116349127241263629572711823",
"length": 894.0
}
},
{
"deprecated": false,
"target": {
"file": "crypto/algif_hash.c",
"function": "hash_accept"
},
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5bff312b59b3f2a54ff504e4f4e47272b64f3633",
"id": "CVE-2025-38079-43e15b2b",
"digest": {
"function_hash": "118233303742603197936831201855101143491",
"length": 727.0
}
},
{
"deprecated": false,
"target": {
"file": "crypto/algif_hash.c"
},
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c3059d58f79fdfb2201249c2741514e34562b547",
"id": "CVE-2025-38079-89debb37",
"digest": {
"threshold": 0.9,
"line_hashes": [
"88193377484234066407793997336907439318",
"332404610381661496299108501612007661699",
"194594963315043819961777364015214110609",
"213539182419324992908857086877119591272",
"134563872701714948476884802856872306636",
"141912292874183711448951172297194083128",
"291091334654150964622877617734807459070"
]
}
},
{
"deprecated": false,
"target": {
"file": "crypto/algif_hash.c",
"function": "hash_accept"
},
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@134daaba93193df9e988524b5cd2f52d15eb1993",
"id": "CVE-2025-38079-8ce70dde",
"digest": {
"function_hash": "30381986374214625331660684086400075000",
"length": 906.0
}
},
{
"deprecated": false,
"target": {
"file": "crypto/algif_hash.c"
},
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@5bff312b59b3f2a54ff504e4f4e47272b64f3633",
"id": "CVE-2025-38079-90dc527f",
"digest": {
"threshold": 0.9,
"line_hashes": [
"88193377484234066407793997336907439318",
"332404610381661496299108501612007661699",
"194594963315043819961777364015214110609",
"213539182419324992908857086877119591272",
"134563872701714948476884802856872306636",
"141912292874183711448951172297194083128",
"291091334654150964622877617734807459070"
]
}
},
{
"deprecated": false,
"target": {
"file": "crypto/algif_hash.c"
},
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2f45a8d64fb4ed4830a4b3273834ecd6ca504896",
"id": "CVE-2025-38079-9ce7a761",
"digest": {
"threshold": 0.9,
"line_hashes": [
"120531522614597963119332194658643133062",
"10506866538608593882138705644182192188",
"194594963315043819961777364015214110609",
"213539182419324992908857086877119591272",
"93036368113892483783502148885477830747",
"287541410922435463826279414099020872436",
"331654088270750618623299079578264099210"
]
}
},
{
"deprecated": false,
"target": {
"file": "crypto/algif_hash.c"
},
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f0f3d09f53534ea385d55ced408f2b67059b16e4",
"id": "CVE-2025-38079-9d3a30d7",
"digest": {
"threshold": 0.9,
"line_hashes": [
"88193377484234066407793997336907439318",
"332404610381661496299108501612007661699",
"194594963315043819961777364015214110609",
"213539182419324992908857086877119591272",
"134563872701714948476884802856872306636",
"141912292874183711448951172297194083128",
"291091334654150964622877617734807459070"
]
}
},
{
"deprecated": false,
"target": {
"file": "crypto/algif_hash.c"
},
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@134daaba93193df9e988524b5cd2f52d15eb1993",
"id": "CVE-2025-38079-af1b7351",
"digest": {
"threshold": 0.9,
"line_hashes": [
"120531522614597963119332194658643133062",
"10506866538608593882138705644182192188",
"194594963315043819961777364015214110609",
"213539182419324992908857086877119591272",
"93036368113892483783502148885477830747",
"287541410922435463826279414099020872436",
"331654088270750618623299079578264099210"
]
}
},
{
"deprecated": false,
"target": {
"file": "crypto/algif_hash.c",
"function": "hash_accept"
},
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@f0f3d09f53534ea385d55ced408f2b67059b16e4",
"id": "CVE-2025-38079-afa057f1",
"digest": {
"function_hash": "118233303742603197936831201855101143491",
"length": 727.0
}
},
{
"deprecated": false,
"target": {
"file": "crypto/algif_hash.c"
},
"signature_type": "Line",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@0346f4b742345d1c733c977f3a7aef5a6419a967",
"id": "CVE-2025-38079-d44f1549",
"digest": {
"threshold": 0.9,
"line_hashes": [
"120531522614597963119332194658643133062",
"10506866538608593882138705644182192188",
"194594963315043819961777364015214110609",
"213539182419324992908857086877119591272",
"93036368113892483783502148885477830747",
"287541410922435463826279414099020872436",
"331654088270750618623299079578264099210"
]
}
},
{
"deprecated": false,
"target": {
"file": "crypto/algif_hash.c",
"function": "hash_accept"
},
"signature_type": "Function",
"signature_version": "v1",
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@c3059d58f79fdfb2201249c2741514e34562b547",
"id": "CVE-2025-38079-e79bf9c4",
"digest": {
"function_hash": "118233303742603197936831201855101143491",
"length": 727.0
}
}
]