Fedora 45 Prepares to Pull the Plug on Risky Kernel Crypto API

Fedora 45 plans to restrict the insecure in-kernel crypto userspace API (AF_ALG/CRYPTO_USER_API) in line with Linux kernel deprecation. Known users like cryptsetup, iwd, and libkcapi remain unaffected in phase one, but migration is urged as upstream removal looms. The controlled rollout identifies unknowns and prevents sudden breakage.
Fedora 45 Prepares to Pull the Plug on Risky Kernel Crypto API
Written by Maya Perez

Fedora is set to restrict a once-promising but now troubled interface. The in-kernel crypto userspace API faces limits in the upcoming Fedora 45 release. This move follows the Linux kernel’s own steps to sideline the feature. But the decision carries real consequences for a handful of tools and users who still rely on it.

The change targets CRYPTO_USER_API. Also known as AF_ALG. It lets user-space programs tap directly into the kernel’s cryptographic functions. Developers added the support back in 2010. Hardware acceleration was the big draw then. Yet that purpose faded. Most kernel developers now view the whole thing as a mistake. Kernel documentation calls it insecure and deprecated. Support lingers only for backwards compatibility.

Why the Kernel Turned Against Its Own Crypto Bridge

Security risks drove the shift. The interface presents a massive attack surface. Recent analysis tied it to concerns around AI and large language model tools probing for weaknesses. Linux 7.2 began the deprecation. Parts of the code started disappearing early in that cycle. Linux 7.3 tightens controls further with sysctl restrictions. Phoronix first reported the deprecation in June 2026. The article highlighted how the feature’s “useless & insecure crypto driver code” was getting removed.

Fedora moves in lockstep. A change proposal landed on July 22, 2026. Owners Peter Robinson and Justin Forbes signed it. The document spells out the goal. “Restrict its use in Fedora early so we can do a controlled ending of support and can make the community aware of its pending disappearance and gracefully deal with unknown users.” The proposal sits in self-contained status. It needs approval from the Fedora Engineering and Steering Committee. Approval looks likely. Upstream momentum leaves little room for reversal.

Known users stay safe in this first phase. The list is short. iwd. Cryptsetup. Libkcapi. That’s it for official Fedora packages. Cryptsetup taps the API for TrueCrypt, tcplay, VeraCrypt compatibility and some benchmarking. It already falls back to other mechanisms. No disruption expected there. Libkcapi serves dracut and the kernel build process. It keeps working too. iwd presents the thorniest case. The Intel wireless daemon uses the API. Yet upstream development sits on hiatus. The Phoronix article from July 24, 2026 notes the package is unmaintained. Users should switch to wpa_supplicant. The interface will continue functioning for now. But the clock ticks.

Phase one deploys upstream patches expected in the 7.3 kernel. These patches lock the API down to only the known applications. The restriction creates a detection mechanism. Any unknown callers surface quickly. Fedora can reach out. Offer migration paths. Document alternatives. The proposal stresses this controlled approach. “Rather than universally pulling the rug without any notice.” A sudden break would anger users. This way feels measured. Almost courteous.

Benefits look clear on paper. Users of the API gain warning time. They can move to other userspace crypto options. The kernel docs recommend disabling CONFIG_CRYPTO_USER_API_* entirely on systems without active programs. Fedora follows that advice. Impact should stay minimal. The feature never saw wide adoption. Most administrators never touched it. Yet for those who did, the change forces homework.

And here’s where details matter. Third-party software could break. Unknown users exist. The proposal acknowledges them. It tasks owners with ensuring migrations happen and replacements get documented. Release engineering faces no extra work. This isn’t a system-wide change. Contingency plans exist. Re-enable the feature if needed. Deadline is general availability. No blocking issues anticipated.

Testing instructions stay straightforward. Install a Fedora build with the 7.2 kernel. Check behavior. User experience should feel unchanged for the vast majority. The proposal states it plainly. “Generally users should not notice.” The kernel Crypto Userspace API was never widely used. Packages that rely on it will shift quietly.

Release notes will carry a blunt message. “Fedora has actively deprecated the in kernel Crypto Userspace API and no longer actively supports its use. If you currently use the userspace crypto API please migrate to another suitable userspace crypto API.” No dedicated documentation exists in Fedora today. That gap itself tells a story. The feature lived on the margins.

This isn’t Fedora acting alone. The Linux kernel set the pace. Its cryptographic subsystem maintainers pushed the deprecation. They cited the attack surface. The limited value. The maintenance burden. Hardware offload support vanished years ago. What remained invited trouble. Recent articles reinforce the point. A June 2026 piece from OSTechnix explained how the change was queued in the crypto tree targeting 7.2. Similar coverage appeared on Reddit’s r/linux forum and daily.dev. The consensus holds. Time to retire it.

Broader implications stretch beyond one distribution. Enterprises running custom kernels or specialized crypto workloads may feel the pinch first. Developers who built tools around AF_ALG face rewrites. The kernel docs now advise clear alternatives for symmetric ciphers, AEAD, and random number generators. User-space libraries like OpenSSL or libsodium offer mature paths. They avoid the kernel context switch overhead in many cases anyway.

So the transition unfolds. Fedora 45 will ship with the restrictions. Unknown users get flagged. Migration guides follow. By the time full removal lands upstream, the ecosystem should stand ready. The move trims attack surface. It simplifies the kernel. It pushes responsibility for crypto to user space where many argue it belongs. Not every interface deserves to live forever. This one showed its age.

Watch the FESCo vote. Track the 7.3 kernel patches. Test your setups now. The rug won’t get pulled. But the warning lights are on. Fedora’s approach gives time to adapt. Smart operators will use it.

Subscribe for Updates

DevNews Newsletter

The DevNews Email Newsletter is essential for software developers, web developers, programmers, and tech decision-makers. Perfect for professionals driving innovation and building the future of tech.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us