Out-of-bounds read in Linux kernel - CVE-2026-80550
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in ccwchain_calc_length() when processing chained channel command words in a channel program. A remote attacker can supply a crafted channel program to disclose sensitive information.
The issue occurs because the routine may examine a 257th CCW entry before rejecting an oversized chain.
Affected software
How to mitigate CVE-2026-80550
External References
- https://git.kernel.org/stable/c/0282fb1c4b638eecfe2cc558092c460911d8f7e2
- https://git.kernel.org/stable/c/499a8a66b1598bfab97182aed15e0f1646074a3d
- https://git.kernel.org/stable/c/4c2e1d359d7a2b82cdf3254e4e480af9417f99fb
- https://git.kernel.org/stable/c/907adc667d902fafbdb2d740d57b55bd025dc4cd
- https://git.kernel.org/stable/c/a005b7f1a491ffda61bff0fd0f6548f8986fb977
- https://git.kernel.org/stable/c/af3f80ca4c8b17f20f9e588def076288fdb49e65
- https://git.kernel.org/stable/c/d5d096cd9369e986d4e5153baa86b8b35c283e09
- https://git.kernel.org/stable/c/f20be33d093ce7630c17ff7ed93caf7eaf8ac1a3