Improper input validation in Linux kernel - CVE-2026-80544
Published: August 27, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information, modify data, or cause a denial of service.
The vulnerability exists due to improper input validation in zcrypt_msgtype6_send_ep11_cprb() when parsing ASN.1-encoded EP11 CPRB payloads. A local user can provide a specially crafted payload to disclose sensitive information, modify data, or cause a denial of service.
The issue affects domain field handling for non-management commands.