CVE-2026-80708
Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
28/08/2026
Última modificación:
28/08/2026
Descripción
*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey()<br />
<br />
The helper function _ip_cprb_helper() uses internal buffer memory for<br />
building and processing CPRBs. After use this buffer was never<br />
scrubbed which could lead to leaving for example clear key material in<br />
memory which could be exposed via tricky reuse of this same memory.<br />
<br />
Extend the _ip_cprb_helper() function with another parameter &#39;scrub&#39;<br />
used to steer scrubbing of this buffer. So now the caller has the<br />
opportunity to decide if scrubbing is needed or not.<br />
<br />
Extend the clear key to secure key token import process in function<br />
cca_clr2cipherkey() to tell the helper function from above to scrub<br />
the cprb buffer when the clear key value is part of the request data.<br />
<br />
Add explicit scrubbing on return from function cca_clr2cipherkey() for<br />
the random EXOR buffer and the cprb buffer.<br />
<br />
Overall this cleans the internal used buffer in case of clear key<br />
import to prevent sensitive data to get exposed.
Impacto
Referencias a soluciones, herramientas e información
- https://git.kernel.org/stable/c/01476391aecef36a3b789ee844357b22fbc90665
- https://git.kernel.org/stable/c/4e26d0d72bfdec311f12acfa0c6b7fbeb6a343d3
- https://git.kernel.org/stable/c/7dd6e556dbfc91d3d511cfd1015d2dad42608010
- https://git.kernel.org/stable/c/8e1c0def77b7450be0ed607ed0d7bae629d30020
- https://git.kernel.org/stable/c/b453003ae6a869f5bdf025b5519cbb38295ae4f1
- https://git.kernel.org/stable/c/be7ae07fb745d1cf575b03a178a055b0a2859364
- https://git.kernel.org/stable/c/ebfbb9ac7adbb1e3556100b54a27e8a9b102feac
- https://git.kernel.org/stable/c/fbb0410986e8ad214121e51a4a28c3d0a10b7644



