๐Ÿ” CVE Alert

CVE-2026-98222

UNKNOWN 0.0

KEYS: encrypted: fix integer overflow of datablob_len

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: KEYS: encrypted: fix integer overflow of datablob_len encrypted_key_alloc() stores datablob_len in a u16. It is computed from multiple string and payload lengths. If the result exceeds U16_MAX, the assignment truncates the allocation size. KASAN reports a 32760-byte slab-out-of-bounds write when __ekey_init() copies the master key description into the undersized buffer. The total payload length stored in key->datalen is also a u16. Use check_add_overflow() to reject values that do not fit either destination, and use kzalloc_flex() for the flexible-array allocation.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
7e70cb4978507cf31d76b90e4cfb4c28cad87f0c < 1e720f63dbafc093a8f5d519f05b67724993edd4 7e70cb4978507cf31d76b90e4cfb4c28cad87f0c < a1a98eca102b1cbbc37ff9eaa197ae4e6a3ea4b0 7e70cb4978507cf31d76b90e4cfb4c28cad87f0c < cca38f2102a4cd35eda8d48950df4817b4b24757 7e70cb4978507cf31d76b90e4cfb4c28cad87f0c < 8697c431e297eb0d0ab13dda6bc172b48a34f05c
Linux / Linux
2.6.38

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/1e720f63dbafc093a8f5d519f05b67724993edd4 git.kernel.org: https://git.kernel.org/stable/c/a1a98eca102b1cbbc37ff9eaa197ae4e6a3ea4b0 git.kernel.org: https://git.kernel.org/stable/c/cca38f2102a4cd35eda8d48950df4817b4b24757 git.kernel.org: https://git.kernel.org/stable/c/8697c431e297eb0d0ab13dda6bc172b48a34f05c