CVE-2026-68125: Linux
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: mac802154: llsec: reject frames shorter than the authentication tag llsec_do_decrypt_auth() computes the associated-data length for the AEAD request as assoclen += datalen - authlen; where datalen is the number of bytes after the MAC header and authlen (4, 8 or 16) is the length of the authentication tag. Nothing verifies that the frame actually carries at least authlen payload bytes. A secured frame whose payload is shorter than the tag makes datalen - authlen negative; assoclen is then passed to aead_request_set_ad() as an unsigned value close to 4 GiB, so crypto_aead_decrypt() walks far off the end of the scatterlist that only spans the real frame. The frame is fully attacker-controlled and reaches this path from any IEEE 802.15.4 peer in radio range. Reject frames whose payload is shorter than the authentication tag before the subtraction. Dynamically reproduced on a KASAN kernel as a general-protection-fault in the AEAD scatterwalk, and the fix confirmed.
Affected products
- Linux Linux: from 3.16, before 5.10.265 (fixed in 5.10.265); from 5.11, before 5.15.216 (fixed in 5.15.216); from 5.16, before 6.1.183 (fixed in 6.1.183); from 6.2, before 6.6.148 (fixed in 6.6.148); from 6.7, before 6.12.101 (fixed in 6.12.101); from 6.13, before 6.18.42 (fixed in 6.18.42); …
Published 2026-08-10. Last modified 2026-08-19.