CVE-2026-68452
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/08/2026
Last modified:
19/08/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
s390/zcrypt: Validate length for CCA AES cipher key requests<br />
<br />
cca_cipher2protkey() derives the copy length for the CPRB parameter<br />
block directly from the length field in the key token. Reject the<br />
request early if the token length exceeds the available space in the<br />
parameter block.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/06afe425d5283b9764303de47f554da5a808ce8a
- https://git.kernel.org/stable/c/3859f630b674801a00bca39bc451f52288591f65
- https://git.kernel.org/stable/c/406b317ea2b501f6f5eca1264293c9399a73a778
- https://git.kernel.org/stable/c/4e500ecb6704d879f9c2417c2ed6faba595015ca
- https://git.kernel.org/stable/c/4fc46deceda076d429ef3fab2ccf8d96629ebd23
- https://git.kernel.org/stable/c/7f9e5a3dbb14a9b321a1dfa30390402c673f82dc
- https://git.kernel.org/stable/c/ad93a1f1a45652478c0cf4eb029114e03af57f3b
- https://git.kernel.org/stable/c/be037204e4f595e4bd2159acda146677a1dc6342



