CVE-2025-68726

CRITICAL

In the Linux kernel, the following vulnerability has been resolved: crypto: aead - Fix reqsize handling Commit afddce13ce81d ("crypto: api - Add reqsize to crypto_alg") introduced cra_reqsize fie...

Affects 0 products across 4 vendors.

BCS3.14
CVSS 3.19.8
EPSS0.4%
Percentile29th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
◆ SAGE Intelligence — CITED Relevance Research Team

A vulnerability in the Linux kernel's crypto subsystem, specifically in the aead (Authenticated Encryption with Associated Data) module, has been identified and resolved. The issue pertains to the handling of the reqsize field in the crypto_alg structure, which was introduced to replace type-specific reqsize fields.

BSID: BS-2025-GLOBAL-030392-I • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2025-68726?
A vulnerability in the Linux kernel's crypto subsystem, specifically in the aead (Authenticated Encryption with Associated Data) module, has been identified and resolved. The issue pertains to the handling of the reqsize field in the crypto_alg structure, which was introduced to replace type-specific reqsize fields.
What is the CVSS score for CVE-2025-68726?
CVE-2025-68726 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.4%.
Is CVE-2025-68726 actively exploited?
No confirmed active exploitation of CVE-2025-68726 as of 2026-07-31.
How do I remediate CVE-2025-68726?
Priority: MEDIUM.
What systems are affected by CVE-2025-68726?
CVE-2025-68726 affects: Crypto, Github, Kernel, Linux.
Vulnerability Details
CVE IDCVE-2025-68726
BSIDBS-2025-GLOBAL-030392-I BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2025-12-24
Last Modified2026-07-30
ICS Relevance0%
Domains
CLOUD
SourceNVD
Official Description

In the Linux kernel, the following vulnerability has been resolved: crypto: aead - Fix reqsize handling Commit afddce13ce81d ("crypto: api - Add reqsize to crypto_alg") introduced cra_reqsize field in crypto_alg struct to replace type specific reqsize fields. It looks like this was introduced specifically for ahash and acomp from the commit description as subsequent commits add necessary changes in these alg frameworks. However, this is being recommended for use in all crypto algs instead of setting reqsize using crypto_*_set_reqsize(). Using cra_reqsize in aead algorithms, hence, causes memory corruptions and crashes as the underlying functions in the algorithm framework have not been updated to set the reqsize properly from cra_reqsize. [1] Add proper set_reqsize calls in the aead init function to properly initialize reqsize for these algorithms in the framework. [1]: https://gist.github.com/Pratham-T/24247446f1faf4b7843e4014d5089f6b

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability could potentially allow an attacker to exploit improper handling of the reqsize field, leading to memory corruption or other unspecified impacts. However, the exact attack vector and potential impact are not fully detailed in the provided information.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Crypto —
Github —
Kernel —
Linux —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 218 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash28d5c3a52c41cbe571f492607822ac9473808f24a9457834c94e8c94117f4bad4bbb39e9d07bc70b2e09ded0c787a1c3301aee81ac3c8a9f35c56385ad8d68e4
Related CVEs affecting Crypto
CVE-2024-32962 10.0 xml-crypto is an xml digital signature and encryption library for Node.js. In... CVE-2026-43493 9.8 In the Linux kernel, the following vulnerability has been resolved: crypto: ... CVE-2024-28285 9.8 A Fault Injection vulnerability in the SymmetricDecrypt function in cryptopp/... CVE-2024-31695 9.8 A misconfiguration in the fingerprint authentication mechanism of Binance: BT... CVE-2025-48141 9.3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Inje...
View all Crypto CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →