Remote Code Execution Risk in Linux Kernel Due to Key Handling Flaw
CVE-2026-80924

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-80924?

A vulnerability exists in the Linux Kernel's handling of derived key buffers within the cryptographic services. The functions responsible for preparing encryption and checksum processes unintentionally free the memory with improperly secured key material. As a result, sensitive data may persist in memory after deallocation, creating a potential pathway for exploitation. Implementing the recommended fixes ensures that derived keys are handled securely without leaving sensitive information exposed.

Affected Version(s)

Linux 3936f02bf2d3308a7359dd37dd96cd60603d8170 < 731a5b6fb4c1705f9405d9029dd64ea81e336207

Linux 3936f02bf2d3308a7359dd37dd96cd60603d8170 < 91b96dc9cc250cd16751f53de525cf3442ca0962

Linux 3936f02bf2d3308a7359dd37dd96cd60603d8170

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.