Linux Kernel Vulnerability in s390/pkey Implementation
CVE-2026-64558
What is CVE-2026-64558?
A vulnerability has been identified in the Linux kernel's s390/pkey implementation. Specifically, the issue arises in the key_to_protkey() handler function, where there was a lack of validation regarding the length of the target buffer. If an output exceeds the maximum buffer length, it can lead to unpredictable behavior or system instability. The vulnerability has been addressed by implementing an explicit length check in the pkey_pckmo handler, ensuring that any output generated is appropriately constrained to fit within the provided target buffer size. Users are encouraged to update their kernel versions to mitigate potential risks associated with this vulnerability.
Affected Version(s)
Linux 8fcc231ce3bea12b78bb94b280cdc03cff342435 < 02028a24e26d85262ab9c8fc4344e1f3503007fc
Linux 8fcc231ce3bea12b78bb94b280cdc03cff342435 < 433e5e70cdc1edf382d28d08a885b22e2b98b7da
Linux 8fcc231ce3bea12b78bb94b280cdc03cff342435 < 614aa0491c7a190556c2345dddee0b6f5ed90989