« Volver al listado

CVE-2026-80543

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

s390/zcrypt: Pad trailing CCA or EP11 message with zeros

The both functions xcrb_msg_to_type6cprb_msgx() and xcrb_msg_to_type6_ep11cprb_msgx() copy the user space message into a kernel buffer based on the message length. But on further processing the message is supposed to be 4 byte length adjusted. Thus up to 3 bytes of uninitialized kernel memory are forwarded to further processing steps and may unwanted expose kernel memory to the crypto card firmware.

This patch contains code to pad the gap between user space copied message and message buffer length sent down to further processing of the CCA or EP11 message to zeros.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-80543",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "e2c6d91eb8b1533753755f07803e47eceed263d0",
              "lessThan": "2db92a56b000173d332b6c30f38a5a4444e4355a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "e2c6d91eb8b1533753755f07803e47eceed263d0",
              "lessThan": "eb363254472493e3458156fc11fd56dca92f4333",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/s390/crypto/zcrypt_msgtype6.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "7.1",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "7.1.10",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/s390/crypto/zcrypt_msgtype6.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-26T15:17:08.657",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/2db92a56b000173d332b6c30f38a5a4444e4355a",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/eb363254472493e3458156fc11fd56dca92f4333",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\ns390/zcrypt: Pad trailing CCA or EP11 message with zeros\n\nThe both functions xcrb_msg_to_type6cprb_msgx() and\nxcrb_msg_to_type6_ep11cprb_msgx() copy the user space message into a\nkernel buffer based on the message length. But on further processing\nthe message is supposed to be 4 byte length adjusted. Thus up to 3\nbytes of uninitialized kernel memory are forwarded to further\nprocessing steps and may unwanted expose kernel memory to the crypto\ncard firmware.\n\nThis patch contains code to pad the gap between user space copied\nmessage and message buffer length sent down to further processing of\nthe CCA or EP11 message to zeros."
    }
  ],
  "lastModified": "2026-08-26T15:17:08.657",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}