Sensitive Information in Resource Not Removed Before Reuse in Linux kernel - CVE-2026-97592

 

Sensitive Information in Resource Not Removed Before Reuse in Linux kernel - CVE-2026-97592

Published: September 28, 2026


Vulnerability identifier: #VU152614
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-97592
CWE-ID: CWE-226
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to failure to clear sensitive data from memory in the s390 AES CTR and GCM cryptographic routines when processing cryptographic requests. A local user can process cryptographic requests that leave sensitive data in temporary buffers to disclose sensitive information.


Affected software

Linux kernel

How to mitigate CVE-2026-97592

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins