{"id":"CVE-2026-28529","summary":"cryptodev-linux \u003c= 1.14 get_userbuf Use After Free LPE","details":"cryptodev-linux version 1.14 and prior contain a page reference handling flaw in the get_userbuf function of the /dev/crypto device driver that allows local users to trigger use-after-free conditions. Attackers with access to the /dev/crypto interface can repeatedly decrement reference counts of controlled pages to achieve local privilege escalation.","modified":"2026-07-16T03:31:12.590417938Z","published":"2026-03-25T13:00:58.783Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-416"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28529.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28529.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28529"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/cryptodev-linux-get-userbuf-use-after-free-lpe"},{"type":"REPORT","url":"https://github.com/cryptodev-linux/cryptodev-linux/pull/104"},{"type":"PACKAGE","url":"https://github.com/cryptodev-linux/cryptodev-linux"},{"type":"EVIDENCE","url":"https://gist.github.com/n4sm/0fd2479e0c23e0fa2f192cd8fda45750"},{"type":"EVIDENCE","url":"https://nasm.re/posts/cryptodev-linux-vuln/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cryptodev-linux/cryptodev-linux","events":[{"introduced":"0"},{"last_affected":"135cbff90af2ba97d88f1472be595ce78721972c"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.14"}],"source":"AFFECTED_FIELD"}}],"versions":["cryptodev-linux-1.14","cryptodev-linux-1.13","cryptodev-linux-1.12","cryptodev-linux-1.11","cryptodev-linux-1.10","cryptodev-linux-1.9","cryptodev-linux-1.8","cryptodev-linux-1.7","cryptodev-linux-1.6","cryptodev-linux-1.5","cryptodev-linux-1.4","cryptodev-linux-1.3","cryptodev-linux-1.2","cryptodev-linux-1.1","cryptodev-linux-1.0","cryptodev-linux-0.9","cryptodev-0.8","cryptodev-linux-0.7","cryptodev-linux-0.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-28529.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}