SB20260727268 - Inclusion of Sensitive Information in Log Files in Linux kernel crypto caam driver
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Inclusion of Sensitive Information in Log Files (CVE-ID: CVE-2026-64316)
CWE-ID: CWE-532 - Information Exposure Through Log Files
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to insertion of sensitive information into log files in the caam crypto driver key-dump code when handling key material in *_setkey() and gen_split_key(). A local user can access debug output containing sensitive key material to disclose sensitive information.
Exposure occurs at runtime when CONFIG_DYNAMIC_DEBUG is enabled.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3f57657b6ea23f933371f2c2846322f441773cee
- https://git.kernel.org/stable/c/45c0e3615e5bca5f1fc93357af8d19975c092d4f
- https://git.kernel.org/stable/c/6f7b8e0321f3a8fbbd267d2ac15c671ab59e919e
- https://git.kernel.org/stable/c/8b56ba10105ca34a4b75f7e33d41d96a63815591
- https://git.kernel.org/stable/c/8cf5fb0503129e53052fe29302379cf83891d0fb
- https://git.kernel.org/stable/c/9a53dc0a0ae0486e164e5af3de5f99ab42c5a23e
- https://git.kernel.org/stable/c/cea7302d5d05df74cfb4107897b1ca34163c06b9
- https://git.kernel.org/stable/c/ebd37eef6e4f435e18829c0c0c9ba3a6618cb2dd