CVE-2026-64312: Linux Kernel

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - restore callback for non-parallel fallback pcrypt installs pcrypt_aead_done() on the child AEAD request before trying to submit it through padata. If padata_do_parallel() returns -EBUSY, pcrypt falls back to calling the child AEAD directly. That fallback must not keep the padata completion callback. Otherwise an asynchronous completion runs pcrypt_aead_done() even though the request was never enrolled in padata. Restore the original request callback and callback data before calling the child AEAD directly. This keeps the fallback path aligned with a direct AEAD request while leaving the parallel path unchanged.

Affected products

  • Linux Linux Kernel: from 4.19.325, before 4.20 (fixed in 4.20); from 5.4.287, before 5.5 (fixed in 5.5); from 5.10.231, before 5.10.261 (fixed in 5.10.261); from 5.15.174, before 5.15.212 (fixed in 5.15.212); from 6.1.120, before 6.1.178 (fixed in 6.1.178); from 6.6.64, before 6.6.145 (fixed in 6.6.145); …

Published 2026-07-25. Last modified 2026-09-03.