CVE Database
/

CVE-2024-26763

Back to search

CVE-2024-26763

Published: Apr 3, 2024

Modified: May 11, 2026

PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: dm-crypt: don't modify the data when using authenticated encryption It was said that authenticated encryption could produce invalid tag when the data that is being encrypted is modified [1]. So, fix this problem by copying the data into the clone bio first and then encrypt them inside the clone bio. This may reduce performance, but it is needed to prevent the user from corrupting the device by writing data with O_DIRECT and modifying them at the same time. [1] https://lore.kernel.org/all/[email protected]/T/

VendorProductVersions

Linux

Linux

affected
ef43aa38063a6b2b3c6618e28ab35794f4f1fe29 - < 43a202bd552976497474ae144942e32cc5f34d7e
affected
ef43aa38063a6b2b3c6618e28ab35794f4f1fe29 - < 0dccbb93538fe89a86c6de31d4b1c8c560848eaa
affected
ef43aa38063a6b2b3c6618e28ab35794f4f1fe29 - < 3c652f6fa1e1f9f02c3fbf359d260ad153ec5f90
affected
ef43aa38063a6b2b3c6618e28ab35794f4f1fe29 - < 1a4371db68a31076afbe56ecce34fbbe6c80c529
affected
ef43aa38063a6b2b3c6618e28ab35794f4f1fe29 - < e08c2a8d27e989f0f5b0888792643027d7e691e6

+3 more versions

Linux

Linux

affected
4.12
unaffected
0 - < 4.12
unaffected
4.19.308 - <= 4.19.*
unaffected
5.4.270 - <= 5.4.*
unaffected
5.10.211 - <= 5.10.*

+5 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now