HIGH Introduced in 2.6.38
keys EncryptedKey Overflow
CVE-2026-98222
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
01Description
In the Linux kernel, the following vulnerability has been resolved: KEYS: encrypted: fix integer overflow of datablob_len encrypted_key_alloc() stores datablob_len in a u16. It is computed from multiple string and payload lengths. If the result exceeds U16_MAX, the assignment truncates the allocation size. KASAN reports a 32760-byte slab-out-of-bounds write when __ekey_init() copies the master key description into the undersized buffer. The total payload length stored in key->datalen is also a u16. Use check_add_overflow() to reject values that do not fit either destination, and use kzalloc_flex() for the flexible-array allocation.
02KernelScan AI Analysis
Risk summary
A local unprivileged user can trigger an integer overflow in the encrypted key allocation logic, causing a heap buffer overflow when the kernel copies key data into an undersized slab object. This can lead to kernel memory corruption, potentially enabling privilege escalation or a system crash. Any system allowing local user code execution is at risk.
Vulnerability analysis
The encrypted key allocation routine computes a total buffer length from several user-supplied string and payload sizes and stores the result in a 16-bit integer. When the sum exceeds the maximum value of that type it silently wraps, producing an allocation far smaller than the data that will later be copied into it. The subsequent initialization step writes the master key description and other fields past the end of the undersized slab object, corrupting adjacent heap memory. The fix replaces the unchecked arithmetic with safe overflow-detection helpers that reject any input whose total length does not fit in the 16-bit field, and switches the allocation to a flexible-array helper so the buffer size is always correct. The vulnerable path is reachable from any local account through the standard key-management syscalls used to create encrypted keys, with no special privileges required.
Lifecycle
03Fix Versions
| Branch | Introduced | Fixed in | Patch commit |
|---|---|---|---|
| 6.12 | 2.6.38 | 6.12.112 | 1e720f63dbaf |
| 6.18 | 2.6.38 | 6.18.54 | a1a98eca102b |
| 7.2 | 2.6.38 | 7.2.8 | cca38f2102a4 |
| mainline | 2.6.38 | 7.3-rc4 | 8697c431e297 |