Linux Kernel Vulnerability in s390/zcrypt Affects Crypto Card Processing
CVE-2026-80709
What is CVE-2026-80709?
An improper limit check in the Linux kernel's s390/zcrypt component can lead to unintended access to heap memory when processing EP11 CPRBs meant for crypto card operations. Specifically, the vulnerability arises from an incorrect domain value verification that only applies to custom device nodes. The flaw can allow administrative CPRBs to bypass intended memory constraints, exposing the system to potential exploitation. The recent update introduces a correct limit check, ensuring the domain values do not exceed the defined maximum (AP_DOMAINS = 256) and enhancing the overall security of crypto card interface operations.
Affected Version(s)
Linux cfd68b33094e1a92249850ff3c3c92ae9112a541 < 4589f742718d0256ea6dd1f5a78be6e689bdb8aa
Linux cfd68b33094e1a92249850ff3c3c92ae9112a541
Linux cfd68b33094e1a92249850ff3c3c92ae9112a541 < 13e53d6ae1c3b2ff1be75b9ef09be26f4ec3ce15