← Back to CVE search

CVE-2026-43336

Linux Kernel

Description

In the Linux kernel, the following vulnerability has been resolved: lib/crypto: chacha: Zeroize permuted_state before it leaves scope Since the ChaCha permutation is invertible, the local variable -permuted_state- is sufficient to compute the original -state-, and thus the key, even after the permutation has been done. While the kernel is quite inconsistent about zeroizing secrets on the stack (and some prominent userspace crypto libraries don-t bother at all since it-s not guaranteed to work anyway), the kernel does try to do it as a best practice, especially in cases involving the RNG. Thus, explicitly zeroize -permuted_state- before it goes out of scope.

CVSS 7.5EPSS 0.42500000000000004%Risk 0.78
View source
Published
2026-05-08 14:16:43
Affected versions
unknown
Type
Core software
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Operating systems
Linux