Use of uninitialized resource in Linux kernel - CVE-2026-80543
Published: August 27, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to exposure of uninitialized memory in xcrb_msg_to_type6cprb_msgx() and xcrb_msg_to_type6_ep11cprb_msgx() in the s390 zcrypt message type 6 handling code when processing user-supplied CCA or EP11 messages with lengths that are not 4-byte aligned. A local user can submit a crafted message to disclose sensitive information.
Up to 3 bytes of uninitialized kernel memory may be forwarded to crypto card firmware during further processing.