CVE-2026-53055
Critical · CVSS 9.8Linux Kernel - hisilicon/sec2 crypto driver — use-after-free (UAF) in crypto request handling
- CVSS
- 9.8
- nvd
- EPSS
- 0.43%
- 35th pct
- KEV
- No
- Class
- oss containerizable
- CWE-416
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec2 - prevent req used-after-free for sec During packet transmission, if the system is under heavy load, the hardware might complete processing the packet and free the request memory (req) before the transmission function finishes. If the software subsequently accesses this req, a use-after-free error will occur. The qp_ctx memory exists throughout the packet sending process, so replace the req with the qp_ctx.
Search profile — drives PoC discovery
Symbols sec2hisiliconqp_ctxreqused-after-freecrypto/hisilicon/sec2sec_reqsec_qp_ctxpacket transmissionhisi_sec2
Keywords CVE-2026-53055hisilicon sec2 use-after-freeLinux kernel crypto sec2 UAFsec2 qp_ctx req freehisilicon crypto driver use-after-freesec2 packet transmission req memorycrypto hisilicon sec2 vulnerabilityLinux kernel sec2 req uaf fix
Versions: Linux kernel versions prior to fixes at commits 67b53a660e6b, ad73563f3a1e, b375c3c7209c
Affected packages
| Linux | Kernel | 6.17.0 → 6.18.33 |
| Linux | Kernel | 6.19.0 → 7.0.10 |
References
Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z