7.8
HIGH CVSS 3.1
CVE-2026-53016
crypto: ccp - copy IV using skcipher ivsize
Description

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - copy IV using skcipher ivsize AF_ALG rfc3686-ctr-aes-ccp requests pass an 8-byte IV to the driver. ccp_aes_complete() restores AES_BLOCK_SIZE bytes into the caller's IV buffer while RFC3686 skciphers expose an 8-byte IV, so the restore overruns the provided buffer. Use crypto_skcipher_ivsize() to copy only the algorithm's IV length.

INFO

Published Date :

June 24, 2026, 5:17 p.m.

Last Modified :

Sept. 16, 2026, 1:18 p.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-53016 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
CVSS Scores
The Common Vulnerability Scoring System is a standardized framework for assessing the severity of vulnerabilities in software and systems. We collect and displays CVSS scores from various sources for each CVE.
Score Version Severity Vector Exploitability Score Impact Score Source
CVSS 3.1 HIGH 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS 3.1 HIGH 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Solution
Fix an out-of-bounds copy in the CCP driver when handling AES-CTR IVs.
  • Use crypto_skcipher_ivsize() to copy IVs.
  • Ensure IV size matches algorithm requirements.
  • Update the Linux kernel to the patched version.
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2026-53016.

URL Resource
https://git.kernel.org/stable/c/227c1e1d9e2aa4cfc65ba446d5690da1f546cda4 Patch
https://git.kernel.org/stable/c/798d409a8949f3f495f238549b86de2886b129bd Patch
https://git.kernel.org/stable/c/939061b2d0f7f15114e34b4ce878ef50ff4089c3 Patch
https://git.kernel.org/stable/c/a7a1f3cdd64d8a165d9b8c9e9ad7fb46ac19dfc4 Patch
https://git.kernel.org/stable/c/bb01d8f1f385bc9034ca114d3508c7fdea24fc9a Patch
https://git.kernel.org/stable/c/df9784bb5b637ac80f4a2768a58ca9a50bef28a9 Patch
https://git.kernel.org/stable/c/dfb2cf434829819268fe50f41542aad318ad62b2 Patch
https://git.kernel.org/stable/c/eecee15e263ccb8cd77170a56ab6c969cb54dd6a Patch
https://access.redhat.com/errata/RHSA-2026:38491 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:39494 Third Party Advisory
https://access.redhat.com/errata/RHSA-2026:55764
https://access.redhat.com/errata/RHSA-2026:55765
https://access.redhat.com/errata/RHSA-2026:56574
https://access.redhat.com/errata/RHSA-2026:59473
https://access.redhat.com/errata/RHSA-2026:59544
https://access.redhat.com/errata/RHSA-2026:61256
https://access.redhat.com/errata/RHSA-2026:64767
https://access.redhat.com/errata/RHSA-2026:65710
https://access.redhat.com/errata/RHSA-2026:67721
https://access.redhat.com/errata/RHSA-2026:67723
https://access.redhat.com/security/cve/CVE-2026-53016 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2492269 Third Party Advisory
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53016.json Third Party Advisory
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-53016 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-53016 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-53016 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-53016 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by 0b0ca135-0b70-47e7-9f44-1890c2a1c46c

    Sep. 16, 2026

    Action Type Old Value New Value
    Added Affected Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/53xxx/CVE-2026-53016.json">CVE-2026-53016</a>
    Added Reference https://access.redhat.com/errata/RHSA-2026:67721
    Added Reference https://access.redhat.com/errata/RHSA-2026:67723
  • CVE Modified by 0b0ca135-0b70-47e7-9f44-1890c2a1c46c

    Sep. 09, 2026

    Action Type Old Value New Value
    Added Affected Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/53xxx/CVE-2026-53016.json">CVE-2026-53016</a>
    Added Reference https://access.redhat.com/errata/RHSA-2026:64767
    Added Reference https://access.redhat.com/errata/RHSA-2026:65710
  • CVE Modified by 0b0ca135-0b70-47e7-9f44-1890c2a1c46c

    Aug. 31, 2026

    Action Type Old Value New Value
    Added Reference https://access.redhat.com/errata/RHSA-2026:61256
  • CVE Modified by 0b0ca135-0b70-47e7-9f44-1890c2a1c46c

    Aug. 26, 2026

    Action Type Old Value New Value
    Added Affected Affected value modified. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/53xxx/CVE-2026-53016.json">CVE-2026-53016</a>
    Added Reference https://access.redhat.com/errata/RHSA-2026:38491
    Added Reference https://access.redhat.com/errata/RHSA-2026:39494
    Added Reference https://access.redhat.com/errata/RHSA-2026:55764
    Added Reference https://access.redhat.com/errata/RHSA-2026:55765
    Added Reference https://access.redhat.com/errata/RHSA-2026:56574
    Added Reference https://access.redhat.com/errata/RHSA-2026:59473
    Added Reference https://access.redhat.com/errata/RHSA-2026:59544
    Added Reference https://access.redhat.com/security/cve/CVE-2026-53016
    Added Reference https://bugzilla.redhat.com/show_bug.cgi?id=2492269
    Added Reference https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53016.json
    Removed Reference https://access.redhat.com/errata/RHSA-2026:38491
    Removed Reference https://access.redhat.com/errata/RHSA-2026:39494
    Removed Reference https://access.redhat.com/errata/RHSA-2026:55764
    Removed Reference https://access.redhat.com/errata/RHSA-2026:55765
    Removed Reference https://access.redhat.com/errata/RHSA-2026:56574
    Removed Reference https://access.redhat.com/security/cve/CVE-2026-53016
    Removed Reference https://bugzilla.redhat.com/show_bug.cgi?id=2492269
    Removed Reference https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53016.json
    Removed Reference Type https://access.redhat.com/errata/RHSA-2026:38491 Types: Third Party Advisory
    Removed Reference Type https://access.redhat.com/errata/RHSA-2026:39494 Types: Third Party Advisory
    Removed Reference Type https://access.redhat.com/security/cve/CVE-2026-53016 Types: Third Party Advisory
    Removed Reference Type https://bugzilla.redhat.com/show_bug.cgi?id=2492269 Types: Third Party Advisory
    Removed Reference Type https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53016.json Types: Third Party Advisory
  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Aug. 26, 2026

    Action Type Old Value New Value
    Added Reference https://git.kernel.org/stable/c/227c1e1d9e2aa4cfc65ba446d5690da1f546cda4
    Added Reference https://git.kernel.org/stable/c/798d409a8949f3f495f238549b86de2886b129bd
    Added Reference https://git.kernel.org/stable/c/939061b2d0f7f15114e34b4ce878ef50ff4089c3
    Added Reference https://git.kernel.org/stable/c/a7a1f3cdd64d8a165d9b8c9e9ad7fb46ac19dfc4
    Added Reference https://git.kernel.org/stable/c/bb01d8f1f385bc9034ca114d3508c7fdea24fc9a
    Added Reference https://git.kernel.org/stable/c/df9784bb5b637ac80f4a2768a58ca9a50bef28a9
    Added Reference https://git.kernel.org/stable/c/dfb2cf434829819268fe50f41542aad318ad62b2
    Added Reference https://git.kernel.org/stable/c/eecee15e263ccb8cd77170a56ab6c969cb54dd6a
    Removed Reference https://git.kernel.org/stable/c/227c1e1d9e2aa4cfc65ba446d5690da1f546cda4
    Removed Reference https://git.kernel.org/stable/c/798d409a8949f3f495f238549b86de2886b129bd
    Removed Reference https://git.kernel.org/stable/c/939061b2d0f7f15114e34b4ce878ef50ff4089c3
    Removed Reference https://git.kernel.org/stable/c/a7a1f3cdd64d8a165d9b8c9e9ad7fb46ac19dfc4
    Removed Reference https://git.kernel.org/stable/c/bb01d8f1f385bc9034ca114d3508c7fdea24fc9a
    Removed Reference https://git.kernel.org/stable/c/df9784bb5b637ac80f4a2768a58ca9a50bef28a9
    Removed Reference https://git.kernel.org/stable/c/dfb2cf434829819268fe50f41542aad318ad62b2
    Removed Reference https://git.kernel.org/stable/c/eecee15e263ccb8cd77170a56ab6c969cb54dd6a
    Removed Reference Type https://git.kernel.org/stable/c/227c1e1d9e2aa4cfc65ba446d5690da1f546cda4 Types: Patch
    Removed Reference Type https://git.kernel.org/stable/c/798d409a8949f3f495f238549b86de2886b129bd Types: Patch
    Removed Reference Type https://git.kernel.org/stable/c/939061b2d0f7f15114e34b4ce878ef50ff4089c3 Types: Patch
    Removed Reference Type https://git.kernel.org/stable/c/a7a1f3cdd64d8a165d9b8c9e9ad7fb46ac19dfc4 Types: Patch
    Removed Reference Type https://git.kernel.org/stable/c/bb01d8f1f385bc9034ca114d3508c7fdea24fc9a Types: Patch
    Removed Reference Type https://git.kernel.org/stable/c/df9784bb5b637ac80f4a2768a58ca9a50bef28a9 Types: Patch
    Removed Reference Type https://git.kernel.org/stable/c/dfb2cf434829819268fe50f41542aad318ad62b2 Types: Patch
    Removed Reference Type https://git.kernel.org/stable/c/eecee15e263ccb8cd77170a56ab6c969cb54dd6a Types: Patch
  • CVE Modified by 0b0ca135-0b70-47e7-9f44-1890c2a1c46c

    Aug. 19, 2026

    Action Type Old Value New Value
    Added Reference https://access.redhat.com/errata/RHSA-2026:56574
  • CVE Modified by 0b0ca135-0b70-47e7-9f44-1890c2a1c46c

    Aug. 18, 2026

    Action Type Old Value New Value
    Added Reference https://access.redhat.com/errata/RHSA-2026:55764
    Added Reference https://access.redhat.com/errata/RHSA-2026:55765
    Changed Affected [{'cpes': ['cpe:/o:redhat:enterprise_linux:10.2'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 10', 'versions': [{'status': 'unaffected', 'version': '0:6.12.0-211.34.1.el10_2', 'lessThan': '*', 'versionType': 'rpm'}], 'packageName': 'kernel', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/a:redhat:enterprise_linux:9', 'cpe:/o:redhat:enterprise_linux:9'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 9', 'versions': [{'status': 'unaffected', 'version': '0:5.14.0-687.25.1.el9_8', 'lessThan': '*', 'versionType': 'rpm'}], 'packageName': 'kernel', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:6'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 6', 'packageName': 'kernel', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'unaffected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:7'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 7', 'packageName': 'kernel', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'unaffected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:7'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 7', 'packageName': 'kernel-rt', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'unaffected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:8'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 8', 'packageName': 'kernel', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:8'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 8', 'packageName': 'kernel-rt', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:9'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 9', 'packageName': 'kernel-rt', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'affected'}] [{'cpes': ['cpe:/o:redhat:enterprise_linux:10.2'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 10', 'versions': [{'status': 'unaffected', 'version': '0:6.12.0-211.34.1.el10_2', 'lessThan': '*', 'versionType': 'rpm'}], 'packageName': 'kernel', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/a:redhat:enterprise_linux:8::nfv'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 8', 'versions': [{'status': 'unaffected', 'version': '0:4.18.0-553.156.1.rt7.497.el8_10', 'lessThan': '*', 'versionType': 'rpm'}], 'packageName': 'kernel-rt', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:8'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 8', 'versions': [{'status': 'unaffected', 'version': '0:4.18.0-553.156.1.el8_10', 'lessThan': '*', 'versionType': 'rpm'}], 'packageName': 'kernel', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/a:redhat:enterprise_linux:9', 'cpe:/o:redhat:enterprise_linux:9'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 9', 'versions': [{'status': 'unaffected', 'version': '0:5.14.0-687.25.1.el9_8', 'lessThan': '*', 'versionType': 'rpm'}], 'packageName': 'kernel', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:6'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 6', 'packageName': 'kernel', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'unaffected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:7'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 7', 'packageName': 'kernel', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'unaffected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:7'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 7', 'packageName': 'kernel-rt', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'unaffected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:9'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 9', 'packageName': 'kernel-rt', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'affected'}]
  • Initial Analysis by [email protected]

    Jul. 15, 2026

    Action Type Old Value New Value
    Added CWE CWE-787
    Added CPE Configuration OR *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.2 up to (excluding) 6.6.141 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.7 up to (excluding) 6.12.91 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.13 up to (excluding) 6.18.33 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 6.19 up to (excluding) 7.0.10 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.16 up to (excluding) 6.1.175 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 5.11 up to (excluding) 5.15.209 *cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* versions from (including) 3.14 up to (excluding) 5.10.258
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/227c1e1d9e2aa4cfc65ba446d5690da1f546cda4 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/798d409a8949f3f495f238549b86de2886b129bd Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/939061b2d0f7f15114e34b4ce878ef50ff4089c3 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/a7a1f3cdd64d8a165d9b8c9e9ad7fb46ac19dfc4 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/bb01d8f1f385bc9034ca114d3508c7fdea24fc9a Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/df9784bb5b637ac80f4a2768a58ca9a50bef28a9 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/dfb2cf434829819268fe50f41542aad318ad62b2 Types: Patch
    Added Reference Type kernel.org: https://git.kernel.org/stable/c/eecee15e263ccb8cd77170a56ab6c969cb54dd6a Types: Patch
    Added Reference Type redhat-SADP: https://access.redhat.com/errata/RHSA-2026:38491 Types: Third Party Advisory
    Added Reference Type redhat-SADP: https://access.redhat.com/errata/RHSA-2026:39494 Types: Third Party Advisory
    Added Reference Type redhat-SADP: https://access.redhat.com/security/cve/CVE-2026-53016 Types: Third Party Advisory
    Added Reference Type redhat-SADP: https://bugzilla.redhat.com/show_bug.cgi?id=2492269 Types: Third Party Advisory
    Added Reference Type redhat-SADP: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53016.json Types: Third Party Advisory
  • CVE Modified by 0b0ca135-0b70-47e7-9f44-1890c2a1c46c

    Jul. 15, 2026

    Action Type Old Value New Value
    Added Reference https://access.redhat.com/errata/RHSA-2026:39494
    Changed Affected [{'cpes': ['cpe:/a:redhat:enterprise_linux:9::appstream'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux AppStream (v. 9)', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:9::baseos'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux BaseOS (v. 9)', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/a:redhat:enterprise_linux:9::crb'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/a:redhat:enterprise_linux:9::nfv'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux Real Time for NFV (v. 9)', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/a:redhat:enterprise_linux:9::realtime'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux Real Time (v. 9)', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:10'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 10', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:8'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 8', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:9'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 9', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:6'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 6', 'defaultStatus': 'unaffected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:7'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 7', 'defaultStatus': 'unaffected'}] [{'cpes': ['cpe:/o:redhat:enterprise_linux:10.2'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 10', 'versions': [{'status': 'unaffected', 'version': '0:6.12.0-211.34.1.el10_2', 'lessThan': '*', 'versionType': 'rpm'}], 'packageName': 'kernel', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/a:redhat:enterprise_linux:9', 'cpe:/o:redhat:enterprise_linux:9'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 9', 'versions': [{'status': 'unaffected', 'version': '0:5.14.0-687.25.1.el9_8', 'lessThan': '*', 'versionType': 'rpm'}], 'packageName': 'kernel', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:6'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 6', 'packageName': 'kernel', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'unaffected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:7'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 7', 'packageName': 'kernel', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'unaffected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:7'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 7', 'packageName': 'kernel-rt', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'unaffected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:8'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 8', 'packageName': 'kernel', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:8'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 8', 'packageName': 'kernel-rt', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:9'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 9', 'packageName': 'kernel-rt', 'collectionURL': 'https://access.redhat.com/downloads/content/package-browser/', 'defaultStatus': 'affected'}]
  • CVE Modified by 0b0ca135-0b70-47e7-9f44-1890c2a1c46c

    Jul. 14, 2026

    Action Type Old Value New Value
    Added Reference https://access.redhat.com/errata/RHSA-2026:38491
    Changed Affected [{'cpes': ['cpe:/o:redhat:enterprise_linux:10'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 10', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:8'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 8', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:9'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 9', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:6'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 6', 'defaultStatus': 'unaffected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:7'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 7', 'defaultStatus': 'unaffected'}] [{'cpes': ['cpe:/a:redhat:enterprise_linux:9::appstream'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux AppStream (v. 9)', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:9::baseos'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux BaseOS (v. 9)', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/a:redhat:enterprise_linux:9::crb'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux CodeReady Linux Builder (v. 9)', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/a:redhat:enterprise_linux:9::nfv'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux Real Time for NFV (v. 9)', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/a:redhat:enterprise_linux:9::realtime'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux Real Time (v. 9)', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:10'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 10', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:8'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 8', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:9'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 9', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:6'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 6', 'defaultStatus': 'unaffected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:7'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 7', 'defaultStatus': 'unaffected'}]
  • CVE Modified by 0b0ca135-0b70-47e7-9f44-1890c2a1c46c

    Jun. 30, 2026

    Action Type Old Value New Value
    Added Affected [{'cpes': ['cpe:/o:redhat:enterprise_linux:10'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 10', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:8'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 8', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:9'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 9', 'defaultStatus': 'affected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:6'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 6', 'defaultStatus': 'unaffected'}, {'cpes': ['cpe:/o:redhat:enterprise_linux:7'], 'vendor': 'Red Hat', 'product': 'Red Hat Enterprise Linux 7', 'defaultStatus': 'unaffected'}]
    Added CVSS V3.1 AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
    Added CWE CWE-805
    Added Reference https://access.redhat.com/security/cve/CVE-2026-53016
    Added Reference https://bugzilla.redhat.com/show_bug.cgi?id=2492269
    Added Reference https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-53016.json
  • CVE Modified by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jun. 28, 2026

    Action Type Old Value New Value
    Added CVSS V3.1 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Jun. 24, 2026

    Action Type Old Value New Value
    Added Affected [{'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '2b789435d7f36ed918d92db647f3a2f3fec9bb1f', 'lessThan': '939061b2d0f7f15114e34b4ce878ef50ff4089c3', 'versionType': 'git'}, {'status': 'affected', 'version': '2b789435d7f36ed918d92db647f3a2f3fec9bb1f', 'lessThan': '798d409a8949f3f495f238549b86de2886b129bd', 'versionType': 'git'}, {'status': 'affected', 'version': '2b789435d7f36ed918d92db647f3a2f3fec9bb1f', 'lessThan': 'dfb2cf434829819268fe50f41542aad318ad62b2', 'versionType': 'git'}, {'status': 'affected', 'version': '2b789435d7f36ed918d92db647f3a2f3fec9bb1f', 'lessThan': 'eecee15e263ccb8cd77170a56ab6c969cb54dd6a', 'versionType': 'git'}, {'status': 'affected', 'version': '2b789435d7f36ed918d92db647f3a2f3fec9bb1f', 'lessThan': 'bb01d8f1f385bc9034ca114d3508c7fdea24fc9a', 'versionType': 'git'}, {'status': 'affected', 'version': '2b789435d7f36ed918d92db647f3a2f3fec9bb1f', 'lessThan': 'df9784bb5b637ac80f4a2768a58ca9a50bef28a9', 'versionType': 'git'}, {'status': 'affected', 'version': '2b789435d7f36ed918d92db647f3a2f3fec9bb1f', 'lessThan': '227c1e1d9e2aa4cfc65ba446d5690da1f546cda4', 'versionType': 'git'}, {'status': 'affected', 'version': '2b789435d7f36ed918d92db647f3a2f3fec9bb1f', 'lessThan': 'a7a1f3cdd64d8a165d9b8c9e9ad7fb46ac19dfc4', 'versionType': 'git'}], 'programFiles': ['drivers/crypto/ccp/ccp-crypto-aes.c'], 'defaultStatus': 'unaffected'}, {'repo': 'https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git', 'vendor': 'Linux', 'product': 'Linux', 'versions': [{'status': 'affected', 'version': '3.14'}, {'status': 'unaffected', 'version': '0', 'lessThan': '3.14', 'versionType': 'semver'}, {'status': 'unaffected', 'version': '5.10.258', 'versionType': 'semver', 'lessThanOrEqual': '5.10.*'}, {'status': 'unaffected', 'version': '5.15.209', 'versionType': 'semver', 'lessThanOrEqual': '5.15.*'}, {'status': 'unaffected', 'version': '6.1.175', 'versionType': 'semver', 'lessThanOrEqual': '6.1.*'}, {'status': 'unaffected', 'version': '6.6.141', 'versionType': 'semver', 'lessThanOrEqual': '6.6.*'}, {'status': 'unaffected', 'version': '6.12.91', 'versionType': 'semver', 'lessThanOrEqual': '6.12.*'}, {'status': 'unaffected', 'version': '6.18.33', 'versionType': 'semver', 'lessThanOrEqual': '6.18.*'}, {'status': 'unaffected', 'version': '7.0.10', 'versionType': 'semver', 'lessThanOrEqual': '7.0.*'}, {'status': 'unaffected', 'version': '7.1', 'versionType': 'original_commit_for_fix', 'lessThanOrEqual': '*'}], 'programFiles': ['drivers/crypto/ccp/ccp-crypto-aes.c'], 'defaultStatus': 'affected'}]
    Added Description In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - copy IV using skcipher ivsize AF_ALG rfc3686-ctr-aes-ccp requests pass an 8-byte IV to the driver. ccp_aes_complete() restores AES_BLOCK_SIZE bytes into the caller's IV buffer while RFC3686 skciphers expose an 8-byte IV, so the restore overruns the provided buffer. Use crypto_skcipher_ivsize() to copy only the algorithm's IV length.
    Added Reference https://git.kernel.org/stable/c/227c1e1d9e2aa4cfc65ba446d5690da1f546cda4
    Added Reference https://git.kernel.org/stable/c/798d409a8949f3f495f238549b86de2886b129bd
    Added Reference https://git.kernel.org/stable/c/939061b2d0f7f15114e34b4ce878ef50ff4089c3
    Added Reference https://git.kernel.org/stable/c/a7a1f3cdd64d8a165d9b8c9e9ad7fb46ac19dfc4
    Added Reference https://git.kernel.org/stable/c/bb01d8f1f385bc9034ca114d3508c7fdea24fc9a
    Added Reference https://git.kernel.org/stable/c/df9784bb5b637ac80f4a2768a58ca9a50bef28a9
    Added Reference https://git.kernel.org/stable/c/dfb2cf434829819268fe50f41542aad318ad62b2
    Added Reference https://git.kernel.org/stable/c/eecee15e263ccb8cd77170a56ab6c969cb54dd6a
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.