Linux maintainers are further dismantling exposed kernel cryptography paths after concluding that several interfaces create unnecessary risk with limited benefit. In the Linux 7.3 cycle, the Qualcomm Crypto Engine (QCE) accelerator driver is being marked BROKEN and dropped from default ARM builds because it is slower than CPU-based cryptography, has a history of bugs, and can trigger race conditions with the secure world due to non-exclusive hardware access. The kernel is also tightening restrictions on AF_ALG, a userspace interface to kernel crypto functions that was deprecated in Linux 7.2 over its broad attack surface and is being constrained further in 7.3.
The fallout is already reaching distributions and encryption tooling. cryptsetup 2.8.7 adds stronger fallback handling to userspace crypto libraries and temporary dm-crypt mappings so encrypted storage can continue working when AF_ALG is unavailable, while warning that some algorithms may still be missing outside the kernel path. Fedora 45 is also planning to remove support for CRYPTO_USER_API, citing architectural and security concerns, limited adoption, and the broader shift away from kernel-exposed crypto APIs after protections tied to the Copy Fail vulnerability affected AF_ALG usage in earlier kernel updates.

See affected versions and whether adversaries are exploiting it.
7 events from the most recent confirmed update back to the earliest known activity.
A Fedora 45 proposal outlined an initial phase for disabling the Linux in-kernel crypto userspace API by limiting access to known applications such as iwd, cryptsetup, and libkcapi. The phased approach was intended to align with Linux 7.2 and planned Linux 7.3 restrictions while identifying unknown users before upstream removal.
Cryptsetup 2.8.7 was released with improved fallback support to userspace crypto libraries and temporary dm-crypt mappings to keep encrypted storage operations working when AF_ALG is disabled or limited. The release also included keyring handling changes, mitigations for possible LUKS volume key digest collisions, and added Aria and Camellia support in the libgcrypt backend.
After the Linux 7.2 deprecation, maintainers further restricted AF_ALG in Linux 7.3. These changes created compatibility fallout for software relying on kernel cryptographic functions from userspace.
Linux maintainers deprecated the AF_ALG userspace cryptography interface in Linux 7.2 because of its large attack surface and security concerns. Fedora-related coverage also ties AF_ALG restrictions to the Copy Fail vulnerability affecting local privilege escalation and container escape scenarios.
For the upcoming Linux 7.3 cycle, the kernel disabled the Qualcomm Crypto Engine Accelerator driver by marking it BROKEN and removing it from default ARMv7 and AArch64 builds. Maintainers cited worse-than-CPU performance, a history of bugs, and security risks from non-exclusive hardware access and race conditions with the secure world.
Fedora 45 plans to remove support for the Linux Crypto Userspace API (CRYPTO_USER_API) because of security, architectural, and maintenance concerns, along with limited practical use. The change was described as part of Fedora 45 planning for 2026.
FESCo approved a proposal for Fedora 45 to adopt the Anaconda WebUI web-based installer, including use for Fedora Atomic Desktop variants such as Silverblue and Kinoite. The installer is intended to support remote installation scenarios.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
9 references tracked. Mallory keeps watching after this page renders.
phoronix.com
Open sourcediscussion.fedoraproject.org
Open sourcemail-archive.com
Open sourcefedoraproject.org
Open sourcelists.fedoraproject.org
Open sourcephoronix.com
Open sourcephoronix.com
Open sourceopennet.ru
Open sourceopennet.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.