Back to overview

CVE-2026-63824

HIGH
7.8
CVSS 3.1
Description
In the Linux kernel, the following vulnerability has been resolved: KEYS: fix overflow in keyctl_pkey_params_get_2() The length for the internal output buffer is calculated incorrectly, which can result overflow when a too small buffer is provided. Fix the bug by allocating internal output with the size of the maximum length of the cryptographic primitive instead of caller provided size.

Metadata

CVE ID
CVE-2026-63824
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 07:54 UTC
Published
2026-07-19 12:02 UTC
Last updated
2026-07-20 13:40 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

7.8 HIGH CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products (2)
VendorProductPlatformVersions
Linux Linux — 00d60fd3b93219ea854220f0fd264b86398cbc53 < 622ec2dcd59f21623f2a7ab773c80ceb7d555e3a, 00d60fd3b93219ea854220f0fd264b86398cbc53 < b1e247338bc71826a2d2def3e0874c34749df69a, 00d60fd3b93219ea854220f0fd264b86398cbc53 < 0f3058d7d26f81df9b68a18ddbe164bdc3c5eff3, 00d60fd3b93219ea854220f0fd264b86398cbc53 < 5966e4e2ba213ab7ad559166152eb4f1f170dd2c …
Linux Linux — 4.20, 0 < 4.20, 5.10.260 ≤ 5.10.*, 5.15.211 ≤ 5.15.* …
CVSS scores (1)
ScoreSeverityVersionSourceVector
7.8 HIGH 3.1 cna CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Back to overview