Bug 2541205 (CVE-2026-97589) - CVE-2026-97589 kernel: s390/crypto: Fix wrong return code to engine in asynch callbacks
Summary: CVE-2026-97589 kernel: s390/crypto: Fix wrong return code to engine in asynch...
Keywords:
Status: NEW
Alias: CVE-2026-97589
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-09-25 11:00 UTC by OSIDB Bzimport
Modified: 2026-09-29 09:52 UTC (History)
17 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-09-25 11:00:41 UTC
In the Linux kernel, the following vulnerability has been resolved:

s390/crypto: Fix wrong return code to engine in asynch callbacks

When crypto_finalize_hash_request() or
crypto_finalize_skcipher_request() explicitly completes a request, the
do_one_request callback must return 0 to indicate successful
handling. Returning a negative error code causes the crypto engine to
assume the driver failed to take ownership and triggers a second
completion via crypto_request_complete(), resulting in a double
completion. This pattern occurs in paes_s390.c 4 times and once in
phmac_s390.c.

Fixed in phmac_do_one_request() and all four paes do_one_request
callbacks (ecb, cbc, ctr, xts) by returning 0 after explicit
finalization instead of propagating the error code.


Note You need to log in before you can comment on or make changes to this bug.