HomeDefectsLIN1025-16035
Fixed

LIN1025-16035 : Security Advisory - linux - CVE-2026-53046

Created: Jun 25, 2026    Updated: Jul 31, 2026
Resolved Date: Jul 31, 2026
Found In Version: 10.25.33.2
Severity: Standard
Applicable for: Wind River Linux LTS 25
Component/s: Kernel

Description

In the Linux kernel, the following vulnerability has been resolved:  ksmbd: fix use-after-free from async crypto on Qualcomm crypto engine  ksmbd_crypt_message() sets a NULL completion callback on AEAD requests and does not handle the -EINPROGRESS return code from async hardware crypto engines like the Qualcomm Crypto Engine (QCE). When QCE returns -EINPROGRESS, ksmbd treats it as an error and immediately frees the request while the hardware DMA operation is still in flight. The DMA completion callback then dereferences freed memory, causing a NULL pointer crash:    pc : qce_skcipher_done+0x24/0x174   lr : vchan_complete+0x230/0x27c   ...   el1h_64_irq+0x68/0x6c   ksmbd_free_work_struct+0x20/0x118 [ksmbd]   ksmbd_exit_file_cache+0x694/0xa4c [ksmbd]  Use the standard crypto_wait_req() pattern with crypto_req_done() as the completion callback, matching the approach used by the SMB client in fs/smb/client/smb2ops.c. This properly handles both synchronous engines (immediate return) and async engines (-EINPROGRESS followed by callback notification).

CVEs