CVE-2026-63824 (GCVE-0-2026-63824)
Vulnerability from cvelistv5
Published
2026-07-19 12:02
Modified
2026-08-17 04:51
Summary
In the Linux kernel, the following vulnerability has been resolved: KEYS: fix overflow in keyctl_pkey_params_get_2() The length for the internal output buffer is calculated incorrectly, which can result overflow when a too small buffer is provided. Fix the bug by allocating internal output with the size of the maximum length of the cryptographic primitive instead of caller provided size.
Impacted products
Vendor Product Version
Linux Linux Version: 00d60fd3b93219ea854220f0fd264b86398cbc53
Version: 00d60fd3b93219ea854220f0fd264b86398cbc53
Version: 00d60fd3b93219ea854220f0fd264b86398cbc53
Version: 00d60fd3b93219ea854220f0fd264b86398cbc53
Version: 00d60fd3b93219ea854220f0fd264b86398cbc53
Version: 00d60fd3b93219ea854220f0fd264b86398cbc53
Version: 00d60fd3b93219ea854220f0fd264b86398cbc53
Version: 00d60fd3b93219ea854220f0fd264b86398cbc53
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "security/keys/keyctl_pkey.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "622ec2dcd59f21623f2a7ab773c80ceb7d555e3a",
              "status": "affected",
              "version": "00d60fd3b93219ea854220f0fd264b86398cbc53",
              "versionType": "git"
            },
            {
              "lessThan": "b1e247338bc71826a2d2def3e0874c34749df69a",
              "status": "affected",
              "version": "00d60fd3b93219ea854220f0fd264b86398cbc53",
              "versionType": "git"
            },
            {
              "lessThan": "0f3058d7d26f81df9b68a18ddbe164bdc3c5eff3",
              "status": "affected",
              "version": "00d60fd3b93219ea854220f0fd264b86398cbc53",
              "versionType": "git"
            },
            {
              "lessThan": "5966e4e2ba213ab7ad559166152eb4f1f170dd2c",
              "status": "affected",
              "version": "00d60fd3b93219ea854220f0fd264b86398cbc53",
              "versionType": "git"
            },
            {
              "lessThan": "5165f1cc727f1322456735df212d8e26ec237a8d",
              "status": "affected",
              "version": "00d60fd3b93219ea854220f0fd264b86398cbc53",
              "versionType": "git"
            },
            {
              "lessThan": "b11c1fa32667692a2c0566e10163758e786e430c",
              "status": "affected",
              "version": "00d60fd3b93219ea854220f0fd264b86398cbc53",
              "versionType": "git"
            },
            {
              "lessThan": "670fc6a311ed321522b7fff92cf0fc376b4f6e78",
              "status": "affected",
              "version": "00d60fd3b93219ea854220f0fd264b86398cbc53",
              "versionType": "git"
            },
            {
              "lessThan": "cb481e59ea6cae3b7796ac1d7a22b6b24c3f3c0b",
              "status": "affected",
              "version": "00d60fd3b93219ea854220f0fd264b86398cbc53",
              "versionType": "git"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "security/keys/keyctl_pkey.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.20"
            },
            {
              "lessThan": "4.20",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.10.*",
              "status": "unaffected",
              "version": "5.10.260",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "5.15.*",
              "status": "unaffected",
              "version": "5.15.211",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.1.*",
              "status": "unaffected",
              "version": "6.1.177",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.6.*",
              "status": "unaffected",
              "version": "6.6.144",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.12.*",
              "status": "unaffected",
              "version": "6.12.95",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.38",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.1.*",
              "status": "unaffected",
              "version": "7.1.3",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.10.260",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "5.15.211",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.1.177",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.6.144",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.12.95",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.38",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.1.3",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2",
                  "versionStartIncluding": "4.20",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nKEYS: fix overflow in keyctl_pkey_params_get_2()\n\nThe length for the internal output buffer is calculated incorrectly, which\ncan result overflow when a too small buffer is provided.\n\nFix the bug by allocating internal output with the size of the maximum\nlength of the cryptographic primitive instead of caller provided size."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The vulnerability is reachable only through the keyctl(2) syscall (KEYCTL_PKEY_ENCRYPT, KEYCTL_PKEY_DECRYPT, or KEYCTL_PKEY_SIGN); there is no network, adjacent, or physical attack path to the affected code.\nAC:L - An attacker fully controls the undersized out_len parameter and can reliably trigger the bug on demand with no races or victim-dependent state; CONFIG_ASYMMETRIC_KEY_TYPE is commonly enabled on server and desktop kernels.\nPR:L - Exploitation requires KEY_NEED_SEARCH on an asymmetric key, which any unprivileged local user can satisfy by loading their own RSA/EC key into a session keyring; no real root or init-namespace capabilities are needed.\nUI:N - Exploitation requires only attacker-initiated keyctl calls and does not depend on any victim user action such as opening a file or mounting a filesystem.\nS:U - Impact is confined to kernel heap memory corruption and privilege escalation within the same kernel security boundary; this is not a VM escape, sandbox escape, or cross-authority boundary violation.\nC:H - When out_len is smaller than the cryptographic output (including out_len=0 where kmalloc(0) yields ZERO_SIZE_PTR), asym_eds_op returns the full primitive output size and copy_to_user reads far beyond the allocated buffer, leaking adjacent kernel heap contents to userspace.\nI:H - The undersized kmalloc buffer is passed directly as the crypto output target; asymmetric operations can write up to the primitive maximum (hundreds of bytes for RSA-4096) past the allocation, enabling heap corruption and potential control-flow hijacking.\nA:H - Heap out-of-bounds read/write against kmalloc objects or writes through ZERO_SIZE_PTR can cause kernel oops, panic, or KASAN-detected corruption, satisfying high availability impact."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-17T04:51:32.494Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/622ec2dcd59f21623f2a7ab773c80ceb7d555e3a"
        },
        {
          "url": "https://git.kernel.org/stable/c/b1e247338bc71826a2d2def3e0874c34749df69a"
        },
        {
          "url": "https://git.kernel.org/stable/c/0f3058d7d26f81df9b68a18ddbe164bdc3c5eff3"
        },
        {
          "url": "https://git.kernel.org/stable/c/5966e4e2ba213ab7ad559166152eb4f1f170dd2c"
        },
        {
          "url": "https://git.kernel.org/stable/c/5165f1cc727f1322456735df212d8e26ec237a8d"
        },
        {
          "url": "https://git.kernel.org/stable/c/b11c1fa32667692a2c0566e10163758e786e430c"
        },
        {
          "url": "https://git.kernel.org/stable/c/670fc6a311ed321522b7fff92cf0fc376b4f6e78"
        },
        {
          "url": "https://git.kernel.org/stable/c/cb481e59ea6cae3b7796ac1d7a22b6b24c3f3c0b"
        }
      ],
      "title": "KEYS: fix overflow in keyctl_pkey_params_get_2()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-63824",
    "datePublished": "2026-07-19T12:02:20.406Z",
    "dateReserved": "2026-07-19T07:54:57.014Z",
    "dateUpdated": "2026-08-17T04:51:32.494Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…