crypto: essiv - Check ssize for decryption and in-place encryption
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: crypto: essiv - Check ssize for decryption and in-place encryption Move the ssize check to the start in essiv_aead_crypt so that it's also checked for decryption and in-place encryption.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-40019
Credits & Attribution
No credits recorded in the NVD database.
References
- https://git.kernel.org/stable/c/29294dd6f1e7acf527255fb136ffde6602c3a129
- https://git.kernel.org/stable/c/71f03f8f72d9c70ffba76980e78b38c180e61589
- https://git.kernel.org/stable/c/df58651968f82344a0ed2afdafd20ecfc55ff548
- https://git.kernel.org/stable/c/248ff2797ff52a8cbf86507f9583437443bf7685
- https://git.kernel.org/stable/c/f37e7860dc5e94c70b4a3e38a5809181310ea9ac
- https://git.kernel.org/stable/c/dc4c854a5e7453c465fa73b153eba4ef2a240abe
- https://git.kernel.org/stable/c/da7afb01ba05577ba3629f7f4824205550644986
- https://git.kernel.org/stable/c/6bb73db6948c2de23e407fe1b7ef94bf02b7529f
More from Linux
View All →Affected Vendor
Linux
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.