Linux Kernel Vulnerability Affecting s390/zcrypt Component
CVE-2026-68451

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
13 August 2026

What is CVE-2026-68451?

A vulnerability in the Linux kernel's s390/zcrypt component relates to the handling of ECC private key requests. The function cca_ecc2protkey() does not properly validate the length of the CCA ECC private key requests, which can lead to improper memory access if the token length exceeds the allocated size for the parameter block. The vulnerability has been mitigated by implementing early rejection of requests that have a length exceeding the space available, thereby enhancing the security of the key management process in this component.

Affected Version(s)

Linux fa6999e326fe7851ecbd572b8cb9be8e930ebf41

Linux fa6999e326fe7851ecbd572b8cb9be8e930ebf41

Linux fa6999e326fe7851ecbd572b8cb9be8e930ebf41 < 013a4484f061a2b41f052e25c0015203287e63f1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.