PT-2026-89094 · Linux · Linux
CVE-2026-80924
·
Published
2026-09-09
·
Updated
2026-09-09
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
In the Linux kernel, the following vulnerability has been resolved:
crypto: krb5 - use kfree sensitive() for derived key buffers
crypto krb5 prepare encryption() and crypto krb5 prepare checksum()
free the buffer holding the freshly derived keys with plain kfree(),
leaving the key material behind in the freed slab object.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux