CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-53055

Critical · CVSS 9.8

Linux Kernel - hisilicon/sec2 crypto driver — use-after-free (UAF) in crypto request handling

CVSS
9.8
nvd
EPSS
0.43%
35th pct
KEV
No
Class
oss containerizable
CWE-416

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/sec2 - prevent req used-after-free for sec During packet transmission, if the system is under heavy load, the hardware might complete processing the packet and free the request memory (req) before the transmission function finishes. If the software subsequently accesses this req, a use-after-free error will occur. The qp_ctx memory exists throughout the packet sending process, so replace the req with the qp_ctx.

Search profile — drives PoC discovery

Symbols sec2hisiliconqp_ctxreqused-after-freecrypto/hisilicon/sec2sec_reqsec_qp_ctxpacket transmissionhisi_sec2
Keywords CVE-2026-53055hisilicon sec2 use-after-freeLinux kernel crypto sec2 UAFsec2 qp_ctx req freehisilicon crypto driver use-after-freesec2 packet transmission req memorycrypto hisilicon sec2 vulnerabilityLinux kernel sec2 req uaf fix
Versions: Linux kernel versions prior to fixes at commits 67b53a660e6b, ad73563f3a1e, b375c3c7209c

Affected packages

Linux Kernel 6.17.0 → 6.18.33
Linux Kernel 6.19.0 → 7.0.10

References

Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z