« Volver al listado

CVE-2026-74566

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

keys: make keyring key-chunk byte order agree with keyring_diff_objects()

keyring_get_key_chunk() loads description bytes into the index chunk low address first, while keyring_diff_objects() numbers the first differing bit from the low end and folds the absolute byte index into the level without removing the inline-prefix offset the level already carries. The two disagree on byte order and bit position, so the array can be told two keys first differ at a bit that does not differ in the chunk the walker uses, letting crafted descriptions collide into one node.

Leer descripción completaMostrar menos

Load the chunk in the order keyring_diff_objects() assumes and drop the inline-prefix length when folding the byte index into the level. This only changes the in-memory ordering used to place keys within a keyring; add, search and read of non-colliding keys are unaffected.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74566",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
              "lessThan": "414bcf37d81ce9b3823aabc06b04c97fdcbe489b",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
              "lessThan": "abe43c661efb753d5ee35ad8ace4bbb16fa9afd0",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
              "lessThan": "f81920917074e3c4ad4fba06fe8c56738d010606",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
              "lessThan": "bd0f976ef89dce6db458bf75bc2cf51127becc41",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
              "lessThan": "7269df3e7fcfa308e6a456305162f7788747bdbd",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
              "lessThan": "3d9f16c0b643ceac305526b2e2fe25c2c6166926",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
              "lessThan": "7e5397a3fed0dee7779bd084bec3c0584db3c930",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
              "lessThan": "58565eef0f8d861aae92abfb7658458d661cee17",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "security/keys/keyring.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "5.3"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "5.3",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.265",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.216",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.183",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.151",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.103",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.44",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.8",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "security/keys/keyring.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-15T13:18:02.120",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3d9f16c0b643ceac305526b2e2fe25c2c6166926",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/414bcf37d81ce9b3823aabc06b04c97fdcbe489b",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/58565eef0f8d861aae92abfb7658458d661cee17",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7269df3e7fcfa308e6a456305162f7788747bdbd",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/7e5397a3fed0dee7779bd084bec3c0584db3c930",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/abe43c661efb753d5ee35ad8ace4bbb16fa9afd0",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/bd0f976ef89dce6db458bf75bc2cf51127becc41",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f81920917074e3c4ad4fba06fe8c56738d010606",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nkeys: make keyring key-chunk byte order agree with keyring_diff_objects()\n\nkeyring_get_key_chunk() loads description bytes into the index chunk low\naddress first, while keyring_diff_objects() numbers the first differing\nbit from the low end and folds the absolute byte index into the level\nwithout removing the inline-prefix offset the level already carries.\nThe two disagree on byte order and bit position, so the array can be\ntold two keys first differ at a bit that does not differ in the chunk\nthe walker uses, letting crafted descriptions collide into one node.\n\nLoad the chunk in the order keyring_diff_objects() assumes and drop the\ninline-prefix length when folding the byte index into the level.  This\nonly changes the in-memory ordering used to place keys within a keyring;\nadd, search and read of non-colliding keys are unaffected."
    }
  ],
  "lastModified": "2026-08-19T17:21:11.443",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}