CVE-2026-98221

Summary

In the Linux kernel, the following vulnerability has been resolved:

KEYS: trusted: Fix tpm2_load_cmd() boundary check

tpm2_load_cmd() does boundary checks against the ASN.1 size i.e., payload->blob_len. Address this by passing the decoded blob size to tpm2_load_cmd(), and use it for the boundary checks.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxf2219745250f388edacabe6cca73654131c67d0a < cc86227fea28aed86c1fb52a884560b4440da198affected
LinuxLinuxf2219745250f388edacabe6cca73654131c67d0a < b020b447338872440142fe8a57350a483da86b7aaffected
LinuxLinuxf2219745250f388edacabe6cca73654131c67d0a < 3fd487c69ad3161e358c33c170bab0cf02a071b7affected
LinuxLinuxf2219745250f388edacabe6cca73654131c67d0a < 5afa57ea91481c6c49f194b0f5a5c4d96a4d7348affected
LinuxLinuxf2219745250f388edacabe6cca73654131c67d0a < 9ddbc5f4bb498aff8096a5231574858a4bffee4faffected
LinuxLinuxf2219745250f388edacabe6cca73654131c67d0a < 134825dfc971fbf2b1d0f58f0b3bce8332ad0afbaffected
LinuxLinuxf2219745250f388edacabe6cca73654131c67d0a < 114f00d738f15dd8c7318369edcdc53dd6d08763affected
LinuxLinux5.13affected
LinuxLinux0 < 5.13unaffected
LinuxLinux5.15.222 <= 5.15.*unaffected
LinuxLinux6.1.189 <= 6.1.*unaffected
LinuxLinux6.6.158 <= 6.6.*unaffected
LinuxLinux6.12.112 <= 6.12.*unaffected
LinuxLinux6.18.54 <= 6.18.*unaffected
LinuxLinux7.2.8 <= 7.2.*unaffected
LinuxLinux7.3-rc4 <= *unaffected

Weaknesses

References