OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97589

HIGH · CVSS 7 EPSS 0.14%

Source: NVD + CISA KEV + EPSS · Published 2026-09-25 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's s390 architecture, specifically in the handling of asynchronous callbacks within cryptographic functions. An incorrect return code in the do_one_request callback can lead to a double completion of crypto requests, potentially compromising the integrity of cryptographic operations. Organizations utilizing Linux on s390 systems, particularly those relying on cryptographic functionalities, should prioritize addressing this issue to mitigate potential security risks.

CVE
CVE-2026-97589
Severity
HIGH
CVSS
7
EPSS
0.14%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: s390/crypto: Fix wrong return code to engine in asynch callbacks When crypto_finalize_hash_request() or crypto_finalize_skcipher_request() explicitly completes a request, the do_one_request callback must return 0 to indicate successful handling. Returning a negative error code causes the crypto engine to assume the driver failed to take ownership and triggers a second completion via crypto_request_complete(), resulting in a double completion. This pattern occurs in paes_s390.c 4 times and once in phmac_s390.c. Fixed in phmac_do_one_request() and all four paes do_one_request callbacks (ecb, cbc, ctr, xts) by returning 0 after explicit finalization instead of propagating the error code.