CVE-2026-80709

Summary

In the Linux kernel, the following vulnerability has been resolved:

s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs

There is a wrong upper limit check for the domain value when an EP11 CPRB is processed for sending to a crypto card. This check is only active on custom device nodes but may lead to access heap memory behind perms->adm when an administrative CPRB is sent. Add correct limit (AP_DOMAINS = 256) checking to fix this.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxcfd68b33094e1a92249850ff3c3c92ae9112a541 < 4589f742718d0256ea6dd1f5a78be6e689bdb8aaaffected
LinuxLinuxcfd68b33094e1a92249850ff3c3c92ae9112a541 < b505dcc8307d64468b463dfad45a03bf865c637eaffected
LinuxLinuxcfd68b33094e1a92249850ff3c3c92ae9112a541 < 13e53d6ae1c3b2ff1be75b9ef09be26f4ec3ce15affected
LinuxLinuxcfd68b33094e1a92249850ff3c3c92ae9112a541 < 672b12940e3f1336dfed5287412a71500adf2a76affected
LinuxLinuxcfd68b33094e1a92249850ff3c3c92ae9112a541 < 1223477ca88e2396eca440919d0ca8754df79bd5affected
LinuxLinuxcfd68b33094e1a92249850ff3c3c92ae9112a541 < 983279d7f86ade73db86f886e09172dd567031b5affected
LinuxLinux5.18affected
LinuxLinux0 < 5.18unaffected
LinuxLinux6.1.183 <= 6.1.*unaffected
LinuxLinux6.6.151 <= 6.6.*unaffected
LinuxLinux6.12.103 <= 6.12.*unaffected
LinuxLinux6.18.44 <= 6.18.*unaffected
LinuxLinux7.1.8 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References