« Volver al listado

CVE-2026-98222

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

KEYS: encrypted: fix integer overflow of datablob_len

encrypted_key_alloc() stores datablob_len in a u16. It is computed from multiple string and payload lengths. If the result exceeds U16_MAX, the assignment truncates the allocation size. KASAN reports a 32760-byte slab-out-of-bounds write when __ekey_init() copies the master key description into the undersized buffer.

The total payload length stored in key->datalen is also a u16. Use check_add_overflow() to reject values that do not fit either destination, and use kzalloc_flex() for the flexible-array allocation.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-98222",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7e70cb4978507cf31d76b90e4cfb4c28cad87f0c",
              "lessThan": "1e720f63dbafc093a8f5d519f05b67724993edd4",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7e70cb4978507cf31d76b90e4cfb4c28cad87f0c",
              "lessThan": "a1a98eca102b1cbbc37ff9eaa197ae4e6a3ea4b0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7e70cb4978507cf31d76b90e4cfb4c28cad87f0c",
              "lessThan": "cca38f2102a4cd35eda8d48950df4817b4b24757",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "7e70cb4978507cf31d76b90e4cfb4c28cad87f0c",
              "lessThan": "8697c431e297eb0d0ab13dda6bc172b48a34f05c",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "security/keys/encrypted-keys/encrypted.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "2.6.38"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "2.6.38",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "6.12.112",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.2.*"
            },
            {
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "security/keys/encrypted-keys/encrypted.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-10-06T09:18:09.153",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/1e720f63dbafc093a8f5d519f05b67724993edd4",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/8697c431e297eb0d0ab13dda6bc172b48a34f05c",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/a1a98eca102b1cbbc37ff9eaa197ae4e6a3ea4b0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/cca38f2102a4cd35eda8d48950df4817b4b24757",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKEYS: encrypted: fix integer overflow of datablob_len\n\nencrypted_key_alloc() stores datablob_len in a u16. It is computed from\nmultiple string and payload lengths. If the result exceeds U16_MAX, the\nassignment truncates the allocation size. KASAN reports a 32760-byte\nslab-out-of-bounds write when __ekey_init() copies the master key\ndescription into the undersized buffer.\n\nThe total payload length stored in key->datalen is also a u16. Use\ncheck_add_overflow() to reject values that do not fit either destination,\nand use kzalloc_flex() for the flexible-array allocation."
    }
  ],
  "lastModified": "2026-10-06T09:18:09.153",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}