Linux Kernel Vulnerability Affecting s390/zcrypt Component
CVE-2026-68451
Currently unrated
What is CVE-2026-68451?
A vulnerability in the Linux kernel's s390/zcrypt component relates to the handling of ECC private key requests. The function cca_ecc2protkey() does not properly validate the length of the CCA ECC private key requests, which can lead to improper memory access if the token length exceeds the allocated size for the parameter block. The vulnerability has been mitigated by implementing early rejection of requests that have a length exceeding the space available, thereby enhancing the security of the key management process in this component.
Affected Version(s)
Linux fa6999e326fe7851ecbd572b8cb9be8e930ebf41
Linux fa6999e326fe7851ecbd572b8cb9be8e930ebf41
Linux fa6999e326fe7851ecbd572b8cb9be8e930ebf41 < 013a4484f061a2b41f052e25c0015203287e63f1