Linux Kernel Vulnerability Affecting s390/zcrypt Product by Linux
CVE-2026-68452
What is CVE-2026-68452?
In the Linux kernel, a vulnerability has been identified in the s390/zcrypt component related to the CCA AES cipher key requests. The issue arises during the copying process of parameters, where the copy length is derived inadequately from the length field in the key token. This oversight can potentially allow requests with token lengths exceeding the defined limits, leading to unexpected behavior. The vulnerability has been addressed by implementing early rejection of requests that exceed the available space in the parameter block, enhancing the overall security of the key management process.
Affected Version(s)
Linux 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd < 406b317ea2b501f6f5eca1264293c9399a73a778
Linux 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd < 4fc46deceda076d429ef3fab2ccf8d96629ebd23
Linux 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd