Improper input validation in Linux kernel - CVE-2026-68452
Published: August 14, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper input validation in cca_cipher2protkey() when processing CCA AES cipher key requests. A local user can supply a key token with an excessive length field to cause a denial of service.
The copy length for the CPRB parameter block is derived directly from the length field in the key token.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-68452
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/06afe425d5283b9764303de47f554da5a808ce8a
- https://git.kernel.org/stable/c/3859f630b674801a00bca39bc451f52288591f65
- https://git.kernel.org/stable/c/406b317ea2b501f6f5eca1264293c9399a73a778
- https://git.kernel.org/stable/c/4fc46deceda076d429ef3fab2ccf8d96629ebd23
- https://git.kernel.org/stable/c/ad93a1f1a45652478c0cf4eb029114e03af57f3b