cbcvebase.
CVE-2026-23222
published 2026-02-18

CVE-2026-23222: In the Linux kernel, the following vulnerability has been resolved: crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly The existing…

PriorityP419medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.13%
2.7th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: omap - Allocate OMAP_CRYPTO_FORCE_COPY scatterlists correctly The existing allocation of scatterlists in omap_crypto_copy_sg_lists() was allocating an array of scatterlist pointers, not scatterlist objects, resulting in a 4x too small allocation. Use sizeof(*new_sg) to get the correct object size.

Affected

66 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
debianlinux-6.1< linux 6.1.164-1 (bookworm)linux 6.1.164-1 (bookworm)
linuxlinux
linuxlinux>= 74ed87e7e7f7197137164738dd0610ccd5ec5ed1 < 953c81941b0ad373674656b8767c00234ebf17ac953c81941b0ad373674656b8767c00234ebf17ac
linuxlinux>= 74ed87e7e7f7197137164738dd0610ccd5ec5ed1 < 31aff96a41ae6f1f1687c065607875a27c364da831aff96a41ae6f1f1687c065607875a27c364da8
linuxlinux>= 74ed87e7e7f7197137164738dd0610ccd5ec5ed1 < 79f95b51d4278044013672c27519ae88d07013d879f95b51d4278044013672c27519ae88d07013d8
linuxlinux>= 74ed87e7e7f7197137164738dd0610ccd5ec5ed1 < 6edf8df4bd29f7bfd245b67b2c31d905f1cfc14b6edf8df4bd29f7bfd245b67b2c31d905f1cfc14b
linuxlinux>= 74ed87e7e7f7197137164738dd0610ccd5ec5ed1 < c184341920ed78b6466360ed7b45b8922586c38fc184341920ed78b6466360ed7b45b8922586c38f
linuxlinux>= 74ed87e7e7f7197137164738dd0610ccd5ec5ed1 < 2ed27b5a1174351148c3adbfc0cd86d54072ba2e2ed27b5a1174351148c3adbfc0cd86d54072ba2e
linuxlinux>= 74ed87e7e7f7197137164738dd0610ccd5ec5ed1 < d1836c628cb72734eb5f7dfd4c996a9c18bba3add1836c628cb72734eb5f7dfd4c996a9c18bba3ad
linuxlinux>= 74ed87e7e7f7197137164738dd0610ccd5ec5ed1 < 1562b1fb7e17c1b3addb15e125c718b2be7f55121562b1fb7e17c1b3addb15e125c718b2be7f5512
linuxlinux_kernel>= 0 < 5.10.251-15.10.251-1
linuxlinux_kernel>= 0 < 6.1.164-16.1.164-1
linuxlinux_kernel>= 0 < 6.12.73-16.12.73-1
linuxlinux_kernel>= 0 < 6.18.12-16.18.12-1
linuxlinux_kernel>= 4.13 < 5.10.2515.10.251
linuxlinux_kernel>= 5.11 < 5.15.2015.15.201
linuxlinux_kernel>= 5.16 < 6.1.1646.1.164
linuxlinux_kernel>= 6.13 < 6.18.116.18.11
linuxlinux_kernel>= 6.19 < 6.19.16.19.1
linuxlinux_kernel>= 6.2 < 6.6.1256.6.125
linuxlinux_kernel>= 6.7 < 6.12.726.12.72
msrcazl3_kernel_6.6.121.1-1_on_azure_linux_3.0
msrccbl2_kernel_5.15.200.1-1_on_cbl_mariner_2.0
ubuntulinux

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu8.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_msrc4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.