Vulnerability in Linux Kernel Affecting s390/pkey Component
CVE-2026-64559

7.8HIGH

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
29 July 2026

What is CVE-2026-64559?

A security vulnerability in the Linux kernel’s s390/pkey component has been identified, where improper validation of buffer length in the PKEY_VERIFYPROTK ioctl call could allow user-space applications to exceed buffer limits. This could potentially lead to data corruption or undefined behavior, thus the need for strict checks on input lengths to enhance the integrity of the system.

Affected Version(s)

Linux 8fcc231ce3bea12b78bb94b280cdc03cff342435 < 0a9e34ccbe772b8f321388cdbdf4f22b94e513e7

Linux 8fcc231ce3bea12b78bb94b280cdc03cff342435 < 693bf91d4db134f9b1c2840c8e287eee3d993bac

Linux 8fcc231ce3bea12b78bb94b280cdc03cff342435 < 7e7e03848c918aa0acad5ffd75d929e3afec1554

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.