Bug 2524454 (CVE-2026-80543) - CVE-2026-80543 kernel: s390/zcrypt: Pad trailing CCA or EP11 message with zeros
Summary: CVE-2026-80543 kernel: s390/zcrypt: Pad trailing CCA or EP11 message with zeros
Keywords:
Status: NEW
Alias: CVE-2026-80543
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-26 14:56 UTC by OSIDB Bzimport
Modified: 2026-09-03 14:47 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-26 14:56:34 UTC
In the Linux kernel, the following vulnerability has been resolved:

s390/zcrypt: Pad trailing CCA or EP11 message with zeros

The both functions xcrb_msg_to_type6cprb_msgx() and
xcrb_msg_to_type6_ep11cprb_msgx() copy the user space message into a
kernel buffer based on the message length. But on further processing
the message is supposed to be 4 byte length adjusted. Thus up to 3
bytes of uninitialized kernel memory are forwarded to further
processing steps and may unwanted expose kernel memory to the crypto
card firmware.

This patch contains code to pad the gap between user space copied
message and message buffer length sent down to further processing of
the CCA or EP11 message to zeros.


Note You need to log in before you can comment on or make changes to this bug.