{"id":"CVE-2026-97589","published":"2026-09-25T11:17:10.103","lastModified":"2026-09-25T15:18:00.547","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/crypto: Fix wrong return code to engine in asynch callbacks\n\nWhen crypto_finalize_hash_request() or\ncrypto_finalize_skcipher_request() explicitly completes a request, the\ndo_one_request callback must return 0 to indicate successful\nhandling. Returning a negative error code causes the crypto engine to\nassume the driver failed to take ownership and triggers a second\ncompletion via crypto_request_complete(), resulting in a double\ncompletion. This pattern occurs in paes_s390.c 4 times and once in\nphmac_s390.c.\n\nFixed in phmac_do_one_request() and all four paes do_one_request\ncallbacks (ecb, cbc, ctr, xts) by returning 0 after explicit\nfinalization instead of propagating the error code.","cvssScore":7,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/5480291aa848e19e61175abfd457933516db70c6","tags":[]},{"url":"https://git.kernel.org/stable/c/972e0d9b7d1d112240ccde1f1be85bf9ffaa1720","tags":[]},{"url":"https://git.kernel.org/stable/c/ac1481320110b803ab9b79ab4d2ca11a74fc05f2","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}