Linux Kernel Vulnerability in s390/zcrypt Affects Crypto Card Processing
CVE-2026-80709

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
28 August 2026

What is CVE-2026-80709?

An improper limit check in the Linux kernel's s390/zcrypt component can lead to unintended access to heap memory when processing EP11 CPRBs meant for crypto card operations. Specifically, the vulnerability arises from an incorrect domain value verification that only applies to custom device nodes. The flaw can allow administrative CPRBs to bypass intended memory constraints, exposing the system to potential exploitation. The recent update introduces a correct limit check, ensuring the domain values do not exceed the defined maximum (AP_DOMAINS = 256) and enhancing the overall security of crypto card interface operations.

Affected Version(s)

Linux cfd68b33094e1a92249850ff3c3c92ae9112a541 < 4589f742718d0256ea6dd1f5a78be6e689bdb8aa

Linux cfd68b33094e1a92249850ff3c3c92ae9112a541

Linux cfd68b33094e1a92249850ff3c3c92ae9112a541 < 13e53d6ae1c3b2ff1be75b9ef09be26f4ec3ce15

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.