Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <DM3PR84MB3444BB73B83ABF54582B9C9F82332@DM3PR84MB3444.NAMPRD84.PROD.OUTLOOK.COM>
Date: Sat, 2 May 2026 23:01:53 +0000
From: "Malik, Vaibhav" <vaibhav.malik@...com>
To: "oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com>
Subject: Re: Re: Re: CVE-2026-31431: CopyFail: linux local
 privilege scalation

Hi,

One flow link or example:

1. Userspace creates AF_ALG socket
A program opens:
socket(AF_ALG, SOCK_SEQPACKET, 0)
Then binds to a crypto algorithm:
"aead" type
algorithm like "gcm(aes)" or "authenc(hmac(sha256),cbc(aes))"

2. Kernel resolves algorithm
Kernel does:
Select crypto template (authenc, gcm, etc.)
Instantiate transformation object in crypto subsystem
Load module if needed and it seems this is where algif_aead becomes active.

Vaibhav

Sent via the Samsung Galaxy S22 Ultra 5G, an AT&T 5G smartphone
Get Outlook for Android<https://aka.ms/AAb9ysg>

________________________________
From: Alexander Bochmann <ab@...ts.gxis.de>
Sent: Saturday, May 2, 2026 3:54:07 PM
To: oss-security@...ts.openwall.com <oss-security@...ts.openwall.com>
Subject: Re: [oss-security] Re: Re: CVE-2026-31431: CopyFail: linux local privilege scalation

CAUTION: External Email

...on 2026-05-02 20:05:00, Eric Biggers wrote:

 > What it does break are a small set of userspace programs that made the
 > shortsighted decision to use AF_ALG, instead of simply following the
 > standard practice of using a userspace crypto library.

For some added fun - I noticed that Debian 13, for example,
ships an openssl build with an AF_ALG engine, so uh, yeah,
depending on how you use your userspace crypto library...

No idea if that has any actual consumers anywhere out there
today.

$ openssl version
OpenSSL 3.5.5 27 Jan 2026 (Library: OpenSSL 3.5.5 27 Jan 2026)
$ openssl engine afalg -c
(afalg) AFALG engine support
 [AES-128-CBC, AES-192-CBC, AES-256-CBC]

Alex.



Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.