Report: CVE-2026-32849 - NetBSD Signed Integer Overflow in cryptodev_op via cryptodev.c

Report: CVE-2026-32849 - NetBSD Signed Integer Overflow in cryptodev_op via cryptodev.c

CVE ID :CVE-2026-32849 Published : May 18, 2026, 6:17 p.m. | 1 hour, 9 minutes ago Description :NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/opencrypto/cryptodev.c where the local variable iov_len is declared as a signed int but assigned from an unsigned cop->dst_len value, causing undefined behavior when cop->dst_len exceeds INT_MAX. A local attacker with access to /dev/crypto and a compression session type can exploit this vulnerability by providing a dst_len value exceeding INT_MAX to trigger a kernel panic through NULL pointer dereference when CONFIG_SVS is disabled and corrupted UIO pointer arithmetic. Severity: 5.7 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
May 18, 2026
Attack Vector: local