Sensitive Information in Resource Not Removed Before Reuse in Linux kernel - CVE-2026-80708

 

Sensitive Information in Resource Not Removed Before Reuse in Linux kernel - CVE-2026-80708

Published: August 28, 2026


Vulnerability identifier: #VU146072
CSH Severity: Low
CVSS v4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80708
CWE-ID: CWE-226
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper clearing of sensitive information in _ip_cprb_helper() and cca_clr2cipherkey() when processing clear key import requests. A local user can trigger clear key import operations and expose residual clear key material from reused memory to disclose sensitive information.

The issue affects internal CPRB buffer memory as well as the random EXOR buffer used during the clear key to secure key token import process.


Affected software

Linux kernel

How to mitigate CVE-2026-80708

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins