CVE-2026-46033

Source
https://cve.org/CVERecord?id=CVE-2026-46033
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46033.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-46033
Downstream
Related
Published
2026-05-27T12:56:42.038Z
Modified
2026-06-05T18:29:26.197609289Z
Summary
crypto: authencesn - reject short ahash digests during instance creation
Details

In the Linux kernel, the following vulnerability has been resolved:

crypto: authencesn - reject short ahash digests during instance creation

authencesn requires either a zero authsize or an authsize of at least 4 bytes because the ESN encrypt/decrypt paths always move 4 bytes of high-order sequence number data at the end of the authenticated data.

While cryptoauthencesnsetauthsize() already rejects explicit non-zero authsizes in the range 1..3, cryptoauthencesncreate() still copied auth->digestsize into inst->alg.maxauthsize without validating it. The AEAD core then initialized the tfm's default authsize from that value.

As a result, selecting an ahash with digest size 1..3, such as cbcmac(ciphernull), exposed authencesn instances whose default authsize was invalid even though setauthsize() would have rejected the same value. AFALG could then trigger the ESN tail handling with a too-short tag and hit an out-of-bounds access.

Reject authencesn instances whose ahash digest size is in the invalid non-zero range 1..3 so that no tfm can inherit an unsupported default authsize.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46033.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f15f05b0a5de667c821a9727c33bce9d1d9b26dd
Fixed
77f59fb2d3aa33e90ec6cbbf45dcfb20ab82b1a9
Fixed
2f31cd1e64a079c845bca31d2da7b3c90a311726
Fixed
d4c6a6d08e70bb1083c7c405fc7faacbf19aebc0
Fixed
b69933e97efea238ebbfcf70c2b1be1cd03f13e3
Fixed
67f1f0933cc3d78dde222842bcad2778ec7a0b88
Fixed
b42821c15445f93daea3e76ada682b2b7181c476
Fixed
9aff81e8217e9de2929084b03b3c7f81988c112b
Fixed
5db6ef9847717329f12c5ea8aba7e9f588a980c0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46033.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.11.0
Fixed
5.10.258
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.209
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.175
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.140
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.86
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.27
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.4

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-46033.json"