Sensitive Information in Resource Not Removed Before Reuse in Linux kernel - CVE-2026-97590
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper clearing of sensitive information in PAES temporary buffers and parameter blocks when processing data with PAES cryptographic operations. A local user can invoke affected PAES cryptographic operations to disclose sensitive information.