CVE-2026-68452: s390/zcrypt: Validate length for CCA AES cipher key requests
In the Linux kernel, the following vulnerability has been resolved:
s390/zcrypt: Validate length for CCA AES cipher key requests
ccacipher2protkey() derives the copy length for the CPRB parameter block directly from the length field in the key token. Reject the request early if the token length exceeds the available space in the parameter block.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-68452?
CVE-2026-68452 has a risk severity rating of 34.
How do I fix CVE-2026-68452?
To fix CVE-2026-68452, ensure that you update your kernel to the version that addresses this vulnerability.
What systems are affected by CVE-2026-68452?
CVE-2026-68452 affects systems running vulnerable versions of the Linux kernel that utilize s390/zcrypt.
What does CVE-2026-68452 involve?
CVE-2026-68452 involves a vulnerability in the Linux kernel related to improper validation of lengths for CCA AES cipher key requests.
When was CVE-2026-68452 published?
CVE-2026-68452 was published on August 13, 2026.