CVE-2026-43033: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption When decrypting data that is not in-place (src != dst), there is no need to save the high-order sequence bits in dst as it could simply be re-copied from the source. However, the data to be hashed need to be rearranged accordingly. Thanks,
Affected products
- Linux Linux Kernel: from 4.3, before 5.10.254 (fixed in 5.10.254); from 5.11, before 5.15.204 (fixed in 5.15.204); from 5.16, before 6.1.170 (fixed in 6.1.170); from 6.2, before 6.6.137 (fixed in 6.6.137); from 6.7, before 6.12.85 (fixed in 6.12.85); from 6.13, before 6.18.22 (fixed in 6.18.22); …
Published 2026-05-01. Last modified 2026-07-14.