CVE-2026-80708
CVE CVE-2026-80708EUVD EUVD-2026-67443Published 2026-08-28T06:53:08.000Z
What the advisory describes
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey() The helper function _ip_cprb_helper() uses internal buffer memory for building and processing CPRBs. After use this buffer was never scrubbed which could lead to leaving for example clear key material in memory which could be exposed via tricky reuse of this same memory. Extend the _ip_cprb_helper() function with another parameter 'scrub' used to steer scrubbing of this buffer. So now the caller has the opportunity to decide if scrubbing is needed or not. Extend the clear key to secure key token import process in function cca_clr2cipherkey() to tell the helper function from above to scrub the cprb buffer when the clear key value is part of the request data. Add explicit scrubbing on return from function cca_clr2cipherkey() for the random EXOR buffer and the cprb buffer. Overall this cleans the internal used buffer in case of clear key import to prevent sensitive data to get exposed.
Source: EUVD (ENISA), in the words of the advisory.
Products the advisory names
These come from the advisory itself, not from any check we performed.
- Linux — Linux 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd <ebfbb9ac7adbb1e3556100b54a27e8a9b102feac; patch: 6.18.44; patch: 6.12.104; patch: 7.2; 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd <be7ae07fb745d1cf575b03a178a055b0a2859364; 5.4; patch: 5.15.216; 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd <01476391aecef36a3b789ee844357b22fbc90665; 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd <fbb0410986e8ad214121e51a4a28c3d0a10b7644; patch: 7.1.8; patch: 6.1.183; patch: 5.10.265; 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd <b453003ae6a869f5bdf025b5519cbb38295ae4f1; patch: 6.6.152; 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd <4e26d0d72bfdec311f12acfa0c6b7fbeb6a343d3; 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd <8e1c0def77b7450be0ed607ed0d7bae629d30020; 4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd <7dd6e556dbfc91d3d511cfd1015d2dad42608010; patch: 0
The versions shown are the advisory's own. Patchlage compares no version numbers and derives no judgement from them — which version is installed is something a person has to look up.
Carried in the product catalogue
An estate covering these products can be recorded in Patchlage. An advisory about them appears in the next morning's situation report.
- Linux — Linux
Does this concern one of your customers?
This page cannot answer that — it does not know your estate. Whoever has recorded their environments gets the answer the morning after publication, together with a paragraph they can forward to the customer unedited.
Try it for 28 daysPatchlage reports hits and suspected hits. About everything else this system says nothing — neither this page nor the situation report ever claims that an estate is safe.