High severity7.8NVD Advisory· Published Aug 13, 2026· Updated Aug 19, 2026
CVE-2026-68451
CVE-2026-68451
Description
In the Linux kernel, the following vulnerability has been resolved:
s390/zcrypt: Validate length for CCA ECC private key requests
cca_ecc2protkey() derives the copy length for the CPRB parameter block directly from the length field in the key token. Reject the request early if the token length exceeds the available space in the parameter block.
Affected products
2Patches
Vulnerability mechanics
References
8- git.kernel.org/stable/c/013a4484f061a2b41f052e25c0015203287e63f1nvd
- git.kernel.org/stable/c/447a37a6bef11bfd3645069e380460b11386e2b9nvd
- git.kernel.org/stable/c/7dc306ff7c4d951582adaae65e0aee9fb4968dbenvd
- git.kernel.org/stable/c/8fa3e9435a13c335efb63fb4f4e77531a0031159nvd
- git.kernel.org/stable/c/a9ae0f6dd45c3ccc1d69363f7aea8af179122730nvd
- git.kernel.org/stable/c/dd25bd9b0f36849808bd7625dcc59dd4c1aeef3envd
- git.kernel.org/stable/c/ecc3b8691c1935f9f3e4eb964ab11e40fdec17f5nvd
- git.kernel.org/stable/c/f0831f13c42c1261d449dcee8a035e1c6cd9fcaanvd
News mentions
0No linked articles in our index yet.