Buffer Over-Read and Under-Run Vulnerability in Linux Kernel s390/zcrypt Component
CVE-2026-68453
What is CVE-2026-68453?
A vulnerability has been discovered in the s390/zcrypt component of the Linux kernel where improper validation of user-controlled fields in CCA token structures can lead to a buffer over-read or under-run. This issue arises when operations on the token structures do not correctly check buffer sizes against actual lengths, potentially allowing an attacker to read beyond allocated memory boundaries or induce kernel crashes by manipulating token length fields. Ensuring that key buffer lengths meet required standards and correspond with token structure sizes is critical for maintaining system integrity and security.
Affected Version(s)
Linux 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd
Linux 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd < 3b2abee2a678607ae27975bc6833785c2002df43
Linux 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd < 36b230835b8a008266aad22168ca52afacc8a58d