{"id":"DEBIAN-CVE-2022-50731","details":"In the Linux kernel, the following vulnerability has been resolved:  crypto: akcipher - default implementation for setting a private key  Changes from v1:   * removed the default implementation from set_pub_key: it is assumed that     an implementation must always have this callback defined as there are     no use case for an algorithm, which doesn't need a public key  Many akcipher implementations (like ECDSA) support only signature verifications, so they don't have all callbacks defined.  Commit 78a0324f4a53 (\"crypto: akcipher - default implementations for request callbacks\") introduced default callbacks for sign/verify operations, which just return an error code.  However, these are not enough, because before calling sign the caller would likely call set_priv_key first on the instantiated transform (as the in-kernel testmgr does). This function does not have a default stub, so the kernel crashes, when trying to set a private key on an akcipher, which doesn't support signature generation.  I've noticed this, when trying to add a KAT vector for ECDSA signature to the testmgr.  With this patch the testmgr returns an error in dmesg (as it should) instead of crashing the kernel NULL ptr dereference.","modified":"2026-09-01T16:05:36.091843459Z","published":"2025-12-24T13:15:59.770Z","upstream":["CVE-2022-50731"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2022-50731"}],"affected":[{"package":{"name":"linux","ecosystem":"Debian:12","purl":"pkg:deb/debian/linux?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50731.json"}},{"package":{"name":"linux","ecosystem":"Debian:13","purl":"pkg:deb/debian/linux?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50731.json"}},{"package":{"name":"linux","ecosystem":"Debian:14","purl":"pkg:deb/debian/linux?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.0.3-1"}]}],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2022-50731.json"}}],"schema_version":"1.9.0"}