PT-2026-89094 · Linux · Linux
CVE-2026-80924
·
Publicado
2026-09-09
·
Atualizado
2026-09-09
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
In the Linux kernel, the following vulnerability has been resolved:
crypto: krb5 - use kfree sensitive() for derived key buffers
crypto krb5 prepare encryption() and crypto krb5 prepare checksum()
free the buffer holding the freshly derived keys with plain kfree(),
leaving the key material behind in the freed slab object.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux