Improper input validation in Linux kernel - CVE-2026-68452

 

Improper input validation in Linux kernel - CVE-2026-68452

Published: August 14, 2026


Vulnerability identifier: #VU142483
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-68452
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to cause a denial of service.

The vulnerability exists due to improper input validation in cca_cipher2protkey() when processing CCA AES cipher key requests. A local user can supply a key token with an excessive length field to cause a denial of service.

The copy length for the CPRB parameter block is derived directly from the length field in the key token.


Affected software

Linux kernel
Debian Linux
linux (Debian package)

How to mitigate CVE-2026-68452

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3
linux (Debian package) - update to 6.12.105-1

External References

Related Security Bulletins