๐Ÿ” CVE Alert

CVE-2026-68148

UNKNOWN 0.0

fscrypt: Add missing superblock check in find_or_insert_direct_key()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: fscrypt: Add missing superblock check in find_or_insert_direct_key() The legacy 'fscrypt_direct_keys' table caches master keys that are used by v1 encryption policies that have FSCRYPT_POLICY_FLAG_DIRECT_KEY. It's just a global table for all filesystems (since the keys can be provided by the legacy process-subscribed keyrings mechanism, which makes it difficult to reuse super_block::s_master_keys). The entries in it ('struct fscrypt_direct_key') do contain a super_block pointer, though, for passing to fscrypt_destroy_inline_crypt_key() when the last inode that references the key is evicted. However, when finding the fscrypt_direct_key for an inode, we weren't actually comparing the super_block pointer. As a result, inodes with different super_blocks could point to the same fscrypt_direct_key. That could extend the lifetime of a fscrypt_direct_key beyond the super_block it points to, causing a use-after-free later. Fix this by creating distinct fscrypt_direct_key structs for distinct super_block structs. Note that this problem doesn't exist in the v2 policy equivalent ("per-mode keys"), since the data structures there are per super_block.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Aug 10, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
22e9947a4b2ba255888541bd0111cf00b9b16586 < 330249609b70778094a7a36f5b6bcfa6362121d4 22e9947a4b2ba255888541bd0111cf00b9b16586 < deff41898a5ae3a47db5fa1896a494aa95efda5d 22e9947a4b2ba255888541bd0111cf00b9b16586 < 95376fe9c145be35566991df99c53134943d992f 22e9947a4b2ba255888541bd0111cf00b9b16586 < 466f187b501a5ac8e1ea2ccf3ccd5c46108d8830 22e9947a4b2ba255888541bd0111cf00b9b16586 < b5fa40226e71c17847b9ff2816c6ca4133d0d994
Linux / Linux
6.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/330249609b70778094a7a36f5b6bcfa6362121d4 git.kernel.org: https://git.kernel.org/stable/c/deff41898a5ae3a47db5fa1896a494aa95efda5d git.kernel.org: https://git.kernel.org/stable/c/95376fe9c145be35566991df99c53134943d992f git.kernel.org: https://git.kernel.org/stable/c/466f187b501a5ac8e1ea2ccf3ccd5c46108d8830 git.kernel.org: https://git.kernel.org/stable/c/b5fa40226e71c17847b9ff2816c6ca4133d0d994