CVE-2026-98222
Received Received - Intake

Integer Overflow in Linux Kernel KEYS Encrypted Key Handling

Vulnerability report for CVE-2026-98222, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: KEYS: encrypted: fix integer overflow of datablob_len encrypted_key_alloc() stores datablob_len in a u16. It is computed from multiple string and payload lengths. If the result exceeds U16_MAX, the assignment truncates the allocation size. KASAN reports a 32760-byte slab-out-of-bounds write when __ekey_init() copies the master key description into the undersized buffer. The total payload length stored in key->datalen is also a u16. Use check_add_overflow() to reject values that do not fit either destination, and use kzalloc_flex() for the flexible-array allocation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
Linux Linux 7e70cb4978507cf31d76b90e4cfb4c28cad87f0c
Linux Linux 7e70cb4978507cf31d76b90e4cfb4c28cad87f0c
Linux Linux 7e70cb4978507cf31d76b90e4cfb4c28cad87f0c
Linux Linux 7e70cb4978507cf31d76b90e4cfb4c28cad87f0c
Linux Linux 2.6.38

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Linux kernel vulnerability where an integer overflow in encrypted_key_alloc() causes a buffer overflow. The function stores datablob_len in a u16, which can overflow if the computed length exceeds U16_MAX. This leads to a slab-out-of-bounds write when copying data into an undersized buffer.

Detection Guidance

This vulnerability is specific to the Linux kernel's encrypted key handling. Detection requires checking kernel logs for KASAN reports of slab-out-of-bounds writes related to encrypted key operations. Monitor dmesg or system logs for errors like 'slab-out-of-bounds' or 'KASAN' warnings.

Impact Analysis

This vulnerability could allow an attacker to execute arbitrary code or cause a denial of service by triggering a buffer overflow in the Linux kernel's key management subsystem.

Mitigation Strategies

Apply the latest Linux kernel patches that fix the integer overflow in encrypted_key_alloc(). Update to a kernel version where check_add_overflow() is used to validate datablob_len and kzalloc_flex() handles allocations safely.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98222. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart