Inclusion of Sensitive Information in Log Files in Linux kernel - CVE-2026-64316
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to insertion of sensitive information into log files in the caam crypto driver key-dump code when handling key material in *_setkey() and gen_split_key(). A local user can access debug output containing sensitive key material to disclose sensitive information.
Exposure occurs at runtime when CONFIG_DYNAMIC_DEBUG is enabled.
Affected software
How to mitigate CVE-2026-64316
External References
- https://git.kernel.org/stable/c/3f57657b6ea23f933371f2c2846322f441773cee
- https://git.kernel.org/stable/c/45c0e3615e5bca5f1fc93357af8d19975c092d4f
- https://git.kernel.org/stable/c/6f7b8e0321f3a8fbbd267d2ac15c671ab59e919e
- https://git.kernel.org/stable/c/8b56ba10105ca34a4b75f7e33d41d96a63815591
- https://git.kernel.org/stable/c/8cf5fb0503129e53052fe29302379cf83891d0fb
- https://git.kernel.org/stable/c/9a53dc0a0ae0486e164e5af3de5f99ab42c5a23e
- https://git.kernel.org/stable/c/cea7302d5d05df74cfb4107897b1ca34163c06b9
- https://git.kernel.org/stable/c/ebd37eef6e4f435e18829c0c0c9ba3a6618cb2dd