PT-2026-89094 · Linux · Linux

CVE-2026-80924

·

Published

2026-09-09

·

Updated

2026-09-09

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the Linux kernel, the following vulnerability has been resolved:
crypto: krb5 - use kfree sensitive() for derived key buffers
crypto krb5 prepare encryption() and crypto krb5 prepare checksum() free the buffer holding the freshly derived keys with plain kfree(), leaving the key material behind in the freed slab object.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-80924

Affected Products

Linux