CVE-2026-43033

Source
https://cve.org/CVERecord?id=CVE-2026-43033
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43033.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-43033
Downstream
Related
Published
2026-05-01T14:15:32.583Z
Modified
2026-05-18T06:00:12.120027610Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption
Details

In the Linux kernel, the following vulnerability has been resolved:

crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption

When decrypting data that is not in-place (src != dst), there is no need to save the high-order sequence bits in dst as it could simply be re-copied from the source.

However, the data to be hashed need to be rearranged accordingly.

Thanks,

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/43xxx/CVE-2026-43033.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
104880a6b470958ddc30e139c41aa4f6ed3a5234
Fixed
8c62f618576519dbed6816fafc623ce592953025
Fixed
d589abd8b019b07075fda255ceab8c8e950cdb3f
Fixed
5466e7d0cd9e4f9cef9d8f18f18b60e7bc1c77e5
Fixed
d0c4ff6812386880f30bc64c2921299cc4d7b47f
Fixed
89fe118b6470119b20c04afc36e45b81a69ea11f
Fixed
153d5520c3f9fd62e71c7e7f9e34b59cf411e555
Fixed
cded4002d22177e8deaca1f257ecd932c9582b6b
Fixed
e02494114ebf7c8b42777c6cd6982f113bfdbec7

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43033.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.3.0
Fixed
5.10.254
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.204
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.170
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.137
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.85
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.22
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.12

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-43033.json"