Vulnerability Details CVE-2026-28529
cryptodev-linux version 1.14 and prior contain a page reference handling flaw in the get_userbuf function of the /dev/crypto device driver that allows local users to trigger use-after-free conditions. Attackers with access to the /dev/crypto interface can repeatedly decrement reference counts of controlled pages to achieve local privilege escalation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 2.1%
CVSS Severity
CVSS v3 Score 7.8
Products affected by CVE-2026-28529
-
cpe:2.3:a:cryptodev-linux:cryptodev-linux:0.6
-
cpe:2.3:a:cryptodev-linux:cryptodev-linux:0.7
-
cpe:2.3:a:cryptodev-linux:cryptodev-linux:0.8
-
cpe:2.3:a:cryptodev-linux:cryptodev-linux:0.9
-
cpe:2.3:a:cryptodev-linux:cryptodev-linux:1.0
-
cpe:2.3:a:cryptodev-linux:cryptodev-linux:1.1
-
cpe:2.3:a:cryptodev-linux:cryptodev-linux:1.10
-
cpe:2.3:a:cryptodev-linux:cryptodev-linux:1.11
-
cpe:2.3:a:cryptodev-linux:cryptodev-linux:1.12
-
cpe:2.3:a:cryptodev-linux:cryptodev-linux:1.13
-
cpe:2.3:a:cryptodev-linux:cryptodev-linux:1.14
-
cpe:2.3:a:cryptodev-linux:cryptodev-linux:1.2
-
cpe:2.3:a:cryptodev-linux:cryptodev-linux:1.3
-
cpe:2.3:a:cryptodev-linux:cryptodev-linux:1.4
-
cpe:2.3:a:cryptodev-linux:cryptodev-linux:1.5
-
cpe:2.3:a:cryptodev-linux:cryptodev-linux:1.6
-
cpe:2.3:a:cryptodev-linux:cryptodev-linux:1.7
-
cpe:2.3:a:cryptodev-linux:cryptodev-linux:1.8
-
cpe:2.3:a:cryptodev-linux:cryptodev-linux:1.9