CVE-2024-43815: Linux Kernel
High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: crypto: mxs-dcp - Ensure payload is zero when using key slot We could leak stack memory through the payload field when running AES with a key from one of the hardware's key slots. Fix this by ensuring the payload field is set to 0 in such cases. This does not affect the common use case when the key is supplied from main memory via the descriptor payload.
Affected products
- Linux Linux Kernel: from 6.10, before 6.10.3 (fixed in 6.10.3)
Published 2024-08-17. Last modified 2026-06-17.