Out-of-Bounds Read Vulnerability in Linux Kernel Asymmetric Key Management
CVE-2026-64544
What is CVE-2026-64544?
A vulnerability in the Linux kernel's asymmetric key management subsystem allows for an out-of-bounds read during the processing of a crafted Portable Executable (PE) file. The issue arises when the method responsible for computing the hash length does not perform sufficient validation on the input, which can lead to an underflow error. If exploited, this can trigger a kernel panic, resulting in system instability and the potential for unauthorized access or control. Implementing safeguards to verify the addition of parameters prior to their use is crucial to prevent exploitation.
Affected Version(s)
Linux af316fc442ef23901bbfcec5af55e69ca6ce9563 < 89efd998470a93284b7ad5a20d4e0e3c6858ae8e
Linux af316fc442ef23901bbfcec5af55e69ca6ce9563 < 7016377699b5b25b7ec3c0bf2ec3f983c7e95f7c
Linux af316fc442ef23901bbfcec5af55e69ca6ce9563