Linux Kernel Vulnerability in s390/pkey Implementation
CVE-2026-64558

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
29 July 2026

What is CVE-2026-64558?

A vulnerability has been identified in the Linux kernel's s390/pkey implementation. Specifically, the issue arises in the key_to_protkey() handler function, where there was a lack of validation regarding the length of the target buffer. If an output exceeds the maximum buffer length, it can lead to unpredictable behavior or system instability. The vulnerability has been addressed by implementing an explicit length check in the pkey_pckmo handler, ensuring that any output generated is appropriately constrained to fit within the provided target buffer size. Users are encouraged to update their kernel versions to mitigate potential risks associated with this vulnerability.

Affected Version(s)

Linux 8fcc231ce3bea12b78bb94b280cdc03cff342435 < 02028a24e26d85262ab9c8fc4344e1f3503007fc

Linux 8fcc231ce3bea12b78bb94b280cdc03cff342435 < 433e5e70cdc1edf382d28d08a885b22e2b98b7da

Linux 8fcc231ce3bea12b78bb94b280cdc03cff342435 < 614aa0491c7a190556c2345dddee0b6f5ed90989

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.