CVE-2026-68148
CVE CVE-2026-68148EUVD EUVD-2026-55533Published 2026-08-10T11:59:13.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: fscrypt: Add missing superblock check in find_or_insert_direct_key() The legacy 'fscrypt_direct_keys' table caches master keys that are used by v1 encryption policies that have FSCRYPT_POLICY_FLAG_DIRECT_KEY. It's just a global table for all filesystems (since the keys can be provided by the legacy process-subscribed keyrings mechanism, which makes it difficult to reuse super_block::s_master_keys). The entries in it ('struct fscrypt_direct_key') do contain a super_block pointer, though, for passing to fscrypt_destroy_inline_crypt_key() when the last inode that references the key is evicted. However, when finding the fscrypt_direct_key for an inode, we weren't actually comparing the super_block pointer. As a result, inodes with different super_blocks could point to the same fscrypt_direct_key. That could extend the lifetime of a fscrypt_direct_key beyond the super_block it points to, causing a use-after-free later. Fix this by creating distinct fscrypt_direct_key structs for distinct super_block structs. Note that this problem doesn't exist in the v2 policy equivalent ("per-mode keys"), since the data structures there are per super_block.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux patch: 7.2-rc5; 22e9947a4b2ba255888541bd0111cf00b9b16586 <b5fa40226e71c17847b9ff2816c6ca4133d0d994; patch: 6.18.42; patch: 7.1.6; patch: 6.12.101; 22e9947a4b2ba255888541bd0111cf00b9b16586 <466f187b501a5ac8e1ea2ccf3ccd5c46108d8830; patch: 0; patch: 6.6.148; 6.1; 22e9947a4b2ba255888541bd0111cf00b9b16586 <deff41898a5ae3a47db5fa1896a494aa95efda5d; 22e9947a4b2ba255888541bd0111cf00b9b16586 <330249609b70778094a7a36f5b6bcfa6362121d4; 22e9947a4b2ba255888541bd0111cf00b9b16586 <95376fe9c145be35566991df99c53134943d992f
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.