๐Ÿ” CVE Alert

CVE-2026-31698

HIGH 7.1

crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed

CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: crypto: ccp: Don't attempt to copy PDH cert to userspace if PSP command failed When retrieving the PDH cert, don't attempt to copy the blobs to userspace if the firmware command failed. If the failure was due to an invalid length, i.e. the userspace buffer+length was too small, copying the number of bytes _firmware_ requires will overflow the kernel-allocated buffer and leak data to userspace. BUG: KASAN: slab-out-of-bounds in instrument_copy_to_user ../include/linux/instrumented.h:129 [inline] BUG: KASAN: slab-out-of-bounds in _inline_copy_to_user ../include/linux/uaccess.h:205 [inline] BUG: KASAN: slab-out-of-bounds in _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26 Read of size 2084 at addr ffff8885c4ab8aa0 by task syz.0.186/21033 CPU: 51 UID: 0 PID: 21033 Comm: syz.0.186 Tainted: G U O 7.0.0-smp-DEV #28 PREEMPTLAZY Tainted: [U]=USER, [O]=OOT_MODULE Hardware name: Google, Inc. Arcadia_IT_80/Arcadia_IT_80, BIOS 34.84.12-0 11/17/2025 Call Trace: <TASK> dump_stack_lvl+0xc5/0x110 ../lib/dump_stack.c:120 print_address_description ../mm/kasan/report.c:378 [inline] print_report+0xbc/0x260 ../mm/kasan/report.c:482 kasan_report+0xa2/0xe0 ../mm/kasan/report.c:595 check_region_inline ../mm/kasan/generic.c:-1 [inline] kasan_check_range+0x264/0x2c0 ../mm/kasan/generic.c:200 instrument_copy_to_user ../include/linux/instrumented.h:129 [inline] _inline_copy_to_user ../include/linux/uaccess.h:205 [inline] _copy_to_user+0x66/0xa0 ../lib/usercopy.c:26 copy_to_user ../include/linux/uaccess.h:236 [inline] sev_ioctl_do_pdh_export+0x3d3/0x7c0 ../drivers/crypto/ccp/sev-dev.c:2347 sev_ioctl+0x2a2/0x490 ../drivers/crypto/ccp/sev-dev.c:2568 vfs_ioctl ../fs/ioctl.c:51 [inline] __do_sys_ioctl ../fs/ioctl.c:597 [inline] __se_sys_ioctl+0x11d/0x1b0 ../fs/ioctl.c:583 do_syscall_x64 ../arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xe0/0x800 ../arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x76/0x7e </TASK> WARN if the driver says the command succeeded, but the firmware error code says otherwise, as __sev_do_cmd_locked() is expected to return -EIO on any firwmware error.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published May 1, 2026
Last Updated Jun 14, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new high vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Linux / Linux
76a2b524a4b1d6dc0f2421f9854a01d55d5e5436 < af67d35da744b6b678c7a0296d9c679658779829 76a2b524a4b1d6dc0f2421f9854a01d55d5e5436 < 854d7846e1d29f32f1bbeb2e869e794df12067f6 76a2b524a4b1d6dc0f2421f9854a01d55d5e5436 < 25d9b3446001185484209cf57951f3368462b631 76a2b524a4b1d6dc0f2421f9854a01d55d5e5436 < b5c14bd4da1f376f385722fe1da993f1edab6472 76a2b524a4b1d6dc0f2421f9854a01d55d5e5436 < 78b97e43d0b3e674d9d49ae56937b11e2ba3fcaf 76a2b524a4b1d6dc0f2421f9854a01d55d5e5436 < 051e51aa55fd4cdc3e8283cf4476aeeb5f563274 76a2b524a4b1d6dc0f2421f9854a01d55d5e5436 < 50808c13452dae43a2c90b1bbbf9daa16501ce70 76a2b524a4b1d6dc0f2421f9854a01d55d5e5436 < e76239fed3cffd6d304d8ca3ce23984fd24f57d3
Linux / Linux
4.16

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/af67d35da744b6b678c7a0296d9c679658779829 git.kernel.org: https://git.kernel.org/stable/c/854d7846e1d29f32f1bbeb2e869e794df12067f6 git.kernel.org: https://git.kernel.org/stable/c/25d9b3446001185484209cf57951f3368462b631 git.kernel.org: https://git.kernel.org/stable/c/b5c14bd4da1f376f385722fe1da993f1edab6472 git.kernel.org: https://git.kernel.org/stable/c/78b97e43d0b3e674d9d49ae56937b11e2ba3fcaf git.kernel.org: https://git.kernel.org/stable/c/051e51aa55fd4cdc3e8283cf4476aeeb5f563274 git.kernel.org: https://git.kernel.org/stable/c/50808c13452dae43a2c90b1bbbf9daa16501ce70 git.kernel.org: https://git.kernel.org/stable/c/e76239fed3cffd6d304d8ca3ce23984fd24f57d3