{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.187-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.1.13-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  crypto: qce - fix CCM AAD buffer underallocation  The AAD buffer allocated in qce_aead_ccm_prepare_buf_assoclen() can be smaller than the length later programmed into the DMA scatterlist.  The allocation size is currently calculated as:    ALIGN(assoclen, 16) + MAX_CCM_ADATA_HEADER_LEN  while the DMA length is set to:    ALIGN(assoclen + adata_header_len, 16)  Since ALIGN() does not distribute over addition, the allocation can be smaller than the DMA length. For example, when assoclen = 32 and adata_header_len = 2:    allocation = ALIGN(32, 16) + 6 = 38   DMA length = ALIGN(32 + 2, 16) = 48  As a result, the QCE hardware can read beyond the allocated buffer while computing the CBC-MAC over the associated data. The extra bytes are folded into the authentication tag, resulting in an incorrect tag and causing CCM self-test failures such as:    alg: aead: ccm-aes-qce encryption test failed (wrong result)   on test vector 8  Fix the allocation by adding the maximum possible AAD header length before alignment:    ALIGN(assoclen + MAX_CCM_ADATA_HEADER_LEN, 16)  This guarantees that the allocated buffer is large enough for the fully padded AAD data for all supported header sizes.",
  "id": "DEBIAN-CVE-2026-80832",
  "modified": "2026-09-14T16:47:46.416425265Z",
  "published": "2026-09-04T16:18:11.433Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-80832"
    }
  ],
  "upstream": [
    "CVE-2026-80832"
  ]
}