Overflow Vulnerability in Linux Kernel Affecting Cryptographic Operations
CVE-2026-63824
What is CVE-2026-63824?
A vulnerability exists in the Linux kernel related to the key management functionality which can lead to a buffer overflow. The issue arises from an incorrect calculation of the internal output buffer length in the keyctl_pkey_params_get_2() function. When a smaller-than-required buffer is provided by the caller, it may lead to an overflow, potentially allowing for unintended behavior or exploitation. This vulnerability has been addressed in recent updates by ensuring that the internal buffer is allocated with the correct maximum size based on the cryptographic primitives, thereby mitigating the risk of overflow.
Affected Version(s)
Linux 00d60fd3b93219ea854220f0fd264b86398cbc53 < 622ec2dcd59f21623f2a7ab773c80ceb7d555e3a
Linux 00d60fd3b93219ea854220f0fd264b86398cbc53
Linux 00d60fd3b93219ea854220f0fd264b86398cbc53 < 0f3058d7d26f81df9b68a18ddbe164bdc3c5eff3