PT-2026-89094 · Linux · Linux

CVE-2026-80924

·

Publicado

2026-09-09

·

Atualizado

2026-09-09

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the Linux kernel, the following vulnerability has been resolved:
crypto: krb5 - use kfree sensitive() for derived key buffers
crypto krb5 prepare encryption() and crypto krb5 prepare checksum() free the buffer holding the freshly derived keys with plain kfree(), leaving the key material behind in the freed slab object.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-80924

Produtos afetados

Linux