PatchSiren cyber security CVE debrief
CVE-2026-43077 Linux CVE debrief
CVE-2026-43077 is a Linux kernel issue in the algif_aead decryption path where the minimum receive-buffer size check did not account for the authentication tag length. The published fix adds the missing extra length so the size check matches decryption requirements. NVD rates the issue as medium severity and lists only availability impact.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-06
- Original CVE updated
- 2026-05-20
- Advisory published
- 2026-05-06
- Advisory updated
- 2026-05-20
Who should care
Linux kernel maintainers, distribution security teams, and operators of systems that use the kernel's AF_ALG/algif_aead crypto interface should review this CVE and ensure patched kernel builds are deployed.
Technical summary
According to the supplied kernel fix description, the decryption receive-size validation in crypto: algif_aead was too small because it did not include the AEAD tag size. That means requests that were sized according to the old check could be rejected or handled incorrectly during decryption. NVD classifies the issue as local, low-privilege, no-user-interaction, availability-only (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Defensive priority
Medium priority for Linux kernel patching, especially on systems that expose or rely on the algif_aead AF_ALG interface.
Recommended defensive actions
- Apply the available Linux kernel patches referenced in the NVD record.
- Upgrade affected kernel branches to the first fixed releases listed by NVD for your track.
- If you cannot patch immediately, reduce exposure by limiting local user access on affected systems where practical.
- Validate that your kernel update process covers all deployed branches, including long-term support lines and release candidates where applicable.
- Monitor for follow-on advisories from your Linux distribution or kernel vendor, but treat the official kernel patch links as the primary remediation source.
Evidence notes
Evidence is limited to the supplied NVD record and linked official kernel patches. NVD marks the vulnerability as analyzed, published on 2026-05-06 and modified on 2026-05-20, with CVSS 5.5 / AV:L / AC:L / PR:L / UI:N / S:U / C:N / I:N / A:H. NVD also provides affected Linux kernel version ranges and official patch references on git.kernel.org. No KEV listing was supplied.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-43077 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-43077
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-43077 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-43077
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/1c76b5675119f694458293a2a81f40731c69bd32
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3afdc15d6173614d7d834517d9b65e7aa5a08548
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/3d14bd48e3a77091cbce637a12c2ae31b4a1687c
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/74a66fdb5282d89e348b00c42cfca3a936946d94
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/78cea133daf721698876e56135049a96d39d610a
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/af2fa2fbbced26129813274b8b3f7705f280e174
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/e86ab1e5661386a874fbb8551f0c04b8e9f8ad22
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.