Buffer Scrubbing Vulnerability in Linux Kernel Affecting s390/zcrypt
CVE-2026-80708
What is CVE-2026-80708?
In the Linux kernel, a buffer scrubbing vulnerability has been identified within the s390/zcrypt component. The issue arises from the internal buffer memory used in the _ip_cprb_helper() function, which is not adequately cleared after use. This oversight could lead to sensitive data, such as clear key material, remaining in memory and potentially being exposed through subsequent memory reuse. To mitigate this risk, enhancements have been implemented in the cca_clr2cipherkey() function to allow explicit scrubbing of the CPRB buffer. This ensures that sensitive information is adequately protected during the clear to secure key import process, preventing unintentional data exposure.
Affected Version(s)
Linux 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd < 8e1c0def77b7450be0ed607ed0d7bae629d30020
Linux 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd
Linux 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd < 4e26d0d72bfdec311f12acfa0c6b7fbeb6a343d3