Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-74566

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
15/08/2026
Última modificación:
15/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> keys: make keyring key-chunk byte order agree with keyring_diff_objects()<br /> <br /> keyring_get_key_chunk() loads description bytes into the index chunk low<br /> address first, while keyring_diff_objects() numbers the first differing<br /> bit from the low end and folds the absolute byte index into the level<br /> without removing the inline-prefix offset the level already carries.<br /> The two disagree on byte order and bit position, so the array can be<br /> told two keys first differ at a bit that does not differ in the chunk<br /> the walker uses, letting crafted descriptions collide into one node.<br /> <br /> Load the chunk in the order keyring_diff_objects() assumes and drop the<br /> inline-prefix length when folding the byte index into the level. This<br /> only changes the in-memory ordering used to place keys within a keyring;<br /> add, search and read of non-colliding keys are unaffected.

Impacto