KernelScan.io

HIGH Introduced in 4.20

KEYS PkeyParams Overflow

CVE-2026-63824

CVSS 7.8 / 10.0 NVD

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

KernelScan AI7.8HIGH

01

In the Linux kernel, the following vulnerability has been resolved: KEYS: fix overflow in keyctl_pkey_params_get_2() The length for the internal output buffer is calculated incorrectly, which can result overflow when a too small buffer is provided. Fix the bug by allocating internal output with the size of the maximum length of the cryptographic primitive instead of caller provided size.

02

Engine v0.4.0

Risk summary

A local unprivileged user can trigger a heap buffer overflow in the kernel's asymmetric key cryptographic operations by supplying a smaller-than-maximum output buffer length via keyctl(). The crypto primitive writes up to its maximum output size into an undersized internally-allocated buffer, leading to kernel heap corruption that can enable privilege escalation, arbitrary code execution, or kernel crash. Any system where unprivileged users or untrusted code can access asymmetric keys is affected.

Affectedsecurity/keys/keyctl_pkey.c (KEYS asymmetric key operations)

Vulnerability analysis

The vulnerability is in keyctl_pkey_params_get_2() in security/keys/keyctl_pkey.c. The function validates that user-supplied in_len and out_len do not exceed the cryptographic primitive's maximum sizes, but then stores the user-supplied out_len (uparams.out_len) directly into params->out_len. The internal output buffer is subsequently allocated based on params->out_len, while the cryptographic operation writes up to the maximum size for the operation (e.g., max_enc_size, max_dec_size, max_sig_size). If the user provides an out_len smaller than the maximum, the allocated buffer is too small and the crypto operation overflows it, causing a heap buffer overflow. The fix replaces the user-supplied out_len with the actual maximum size for the operation so the internal buffer is always large enough. The attack surface is local: any process that can call keyctl() with KEYCTL_PKEY_ENCRYPT/DECRYPT/SIGN/VERIFY and has access to an asymmetric key can trigger this. No special privileges beyond key access are required, making this reachable by unprivileged local users and container tenants.

03

BranchIntroducedFixed inPatch commit
5.104.205.10.260622ec2dcd59f
5.154.205.15.211b1e247338bc7
6.14.206.1.1770f3058d7d26f
6.64.206.6.1445966e4e2ba21
6.124.206.12.955165f1cc727f
6.184.206.18.38b11c1fa32667
7.14.207.1.3670fc6a311ed
mainline4.207.2-rc1cb481e59ea6c