Improper input validation in Linux kernel - CVE-2026-64559
Published: July 30, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary code or cause a denial of service.
The vulnerability exists due to improper input validation in the PKEY_VERIFYPROTK ioctl in drivers/s390/crypto/pkey_api.c when processing a user-supplied request structure from user space. A local user can provide a crafted buffer length value to execute arbitrary code or cause a denial of service.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-64559
linux (Debian package) - update to 6.12.100-1