Linux Kernel ESSIV Decryption and In-Place Encryption Size Check Vulnerability

Vulnerability

A vulnerability in the Linux kernel's ESSIV (Encrypted Sectors Initialization Vector) implementation has been addressed. The issue involved improper handling of the size of associated data during decryption and in-place encryption, which could potentially lead to incorrect processing of cryptographic operations. The vulnerability was present in the stable versions of the Linux kernel.

Impact

The vulnerability could cause incorrect decryption or in-place encryption, potentially leading to data corruption or cryptographic errors.

Reproduction

The vulnerability can be reproduced by using the ESSIV encryption scheme in a context where decryption or in-place encryption is performed. The associated data length must be manipulated to create a scenario where the size check is bypassed, allowing for improper handling of the encryption process.

Remediation

Users can upgrade to the latest version of the Linux kernel where this vulnerability has been fixed. Instructions for downloading the patched version are available on the official Linux kernel website.

Added: Oct 24, 2025, 12:18 PM
Updated: Oct 24, 2025, 12:18 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
5.7
remediation
7.7
relevance
0.8
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.