Buffer Scrubbing Vulnerability in Linux Kernel Affecting s390/zcrypt
CVE-2026-80708

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-80708?

In the Linux kernel, a buffer scrubbing vulnerability has been identified within the s390/zcrypt component. The issue arises from the internal buffer memory used in the _ip_cprb_helper() function, which is not adequately cleared after use. This oversight could lead to sensitive data, such as clear key material, remaining in memory and potentially being exposed through subsequent memory reuse. To mitigate this risk, enhancements have been implemented in the cca_clr2cipherkey() function to allow explicit scrubbing of the CPRB buffer. This ensures that sensitive information is adequately protected during the clear to secure key import process, preventing unintentional data exposure.

Affected Version(s)

Linux 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd < 8e1c0def77b7450be0ed607ed0d7bae629d30020

Linux 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd

Linux 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd < 4e26d0d72bfdec311f12acfa0c6b7fbeb6a343d3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.