CVE-2025-68726
A flaw in how the Linux kernel handles memory sizes within certain encryption functions can lead to system instability. Specifically, the way certain cryptographic algorithms manage request sizes can cause memory corruption.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users running affected versions of the Linux kernel that utilize specific authenticated encryption (AEAD) algorithms.
Real-world impact
An attacker could potentially cause a system crash or trigger memory corruption, which could lead to unpredictable system behavior or a complete system failure.
Why this severity
This vulnerability is rated critical because it can be exploited remotely without authentication or user interaction, and it can lead to a total loss of confidentiality, integrity, and availability.
What to do about it
- 01Apply the fix for the Linux kernel regarding crypto: aead reqsize handling.
NVD-referenced vendor advisory
Timeline
- Dec 24, 2025 · Dec 24, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Jul 30, 2026 · 6d agoAdvisory updatedThe NVD record was last revised.
- Jul 30, 2026 · 6d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.