Missing Encryption of Sensitive Data in Linux kernel - CVE-2026-80806
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to cause sensitive data to be stored without encryption.
The vulnerability exists due to incorrect initialization order of encryption flags in the ext4 __ext4_new_inode() function when creating a new encrypted regular file on an ext4 filesystem mounted with dax=always. A local user can create a new encrypted regular file and write data to it to cause sensitive data to be stored without encryption.
Affected software
How to mitigate CVE-2026-80806
External References
- https://git.kernel.org/stable/c/3392391b363a63ebb531d45318a729b1c998565b
- https://git.kernel.org/stable/c/458776af0061afec1014cb3cd0061e282e482e83
- https://git.kernel.org/stable/c/5959cad3cfa852ec07bbdaf9c17f4838a94a8e6c
- https://git.kernel.org/stable/c/a13f61ba9b2a7a4ff1f140949ccfad23c5313757
- https://git.kernel.org/stable/c/add98959b220935b243170214c787bc03044a44d
- https://git.kernel.org/stable/c/da32af420d6d466e247c43ac0b829edeac7ae0ad
- https://git.kernel.org/stable/c/e27bae352158c007143d5bb50f3af33a177c0a37
- https://git.kernel.org/stable/c/ed1cd834da65db127f1c30ff67e78f14825a06c1
- https://git.kernel.org/stable/c/f53b325068bca0b238c3e0d2eb7de9b1f2268cab