CVE-2026-80652: crypto: ccp - Treat zero-length cert chain as query for blob lengths
In the Linux kernel, the following vulnerability has been resolved:
crypto: ccp - Treat zero-length cert chain as query for blob lengths
When handling a PDH export, treat a zero-length userspace cert chain buffer as a request to query the length of the relevant blobs. Failure to account for the zero-length buffer trips a BUGON() when running with CONFIGDEBUGVIRTUAL=y due to trying to get the physical address of the ZEROSIZEPTR (returned by kzalloc() on the bogus allocation).
kernel BUG at arch/x86/mm/physaddr.c:28 ! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI CPU: 30 UID: 0 PID: 28580 Comm: syz.2.18 Kdump: loaded Tainted: G W 6.18.16-smp-DEV #1 NONE Tainted: [W]=WARN Hardware name: Google, Inc. ArcadiaIT80/ArcadiaIT80, BIOS 12.62.0-0 11/19/2025 RIP: 0010:physaddr+0x16a/0x180 arch/x86/mm/physaddr.c:28 RSP: 0018:ffffc9008329fc80 EFLAGS: 00010293 RAX: ffffffff8179110a RBX: 0000778000000010 RCX: ffff8884e6992600 RDX: 0000000000000000 RSI: 0000000080000010 RDI: 0000778000000010 RBP: ffffc9008329fdf0 R08: 0000000000000dc0 R09: 00000000ffffffff R10: dffffc0000000000 R11: fffffbfff126d297 R12: dffffc0000000000 R13: 1ffff92010653fc8 R14: 0000000080000010 R15: dffffc0000000000 FS: 0000555556bec9c0(0000) GS:ffff88aa4ce1c000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007fd3159e7000 CR3: 00000004fbc44000 CR4: 0000000000350ef0 Call Trace: <TASK> [<ffffffff853d3869>] sevioctldopdhexport+0x559/0x7a0 drivers/crypto/ccp/sev-dev.c:2308 [<ffffffff853d1fdd>] sevioctl+0x2cd/0x480 drivers/crypto/ccp/sev-dev.c:2556 [<ffffffff82549ebc>] vfsioctl fs/ioctl.c:52 [inline] [<ffffffff82549ebc>] dosysioctl fs/ioctl.c:598 [inline] [<ffffffff82549ebc>] sesysioctl+0xfc/0x170 fs/ioctl.c:584 [<ffffffff8630115f>] dosyscallx64 arch/x86/entry/syscall64.c:64 [inline] [<ffffffff8630115f>] dosyscall64+0x9f/0xf40 arch/x86/entry/syscall64.c:98 [<ffffffff81000136>] entrySYSCALL64afterhwframe+0x76/0x7e RIP: 0033:0x7fd3158eac39 </TASK>
Thankfully, the bug is benign outside of CONFIGDEBUGVIRTUAL=y as getting the physical address is just arithmetic, and the PSP errors out before trying to write to the garbage address (which it must, otherwise querying the blob lengths would clobber memory at pfn=0).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 6.18.16-smp-DEV #1Patch crypto: ccp - Treat zero-length cert chain as query for blob lengths - Configuration
Disable CONFIG_DEBUG_VIRTUAL=y because the issue is described as benign outside of CONFIG_DEBUG_VIRTUAL=y.
Linux kernel (CONFIG_DEBUG_VIRTUAL) CONFIG_DEBUG_VIRTUAL = not enabled (unset/disable)
Event History
Frequently Asked Questions
Which systems are most likely to exhibit the failure?
The reported BUG is triggered when CONFIG_DEBUG_VIRTUAL is enabled. The affected path is the Linux kernel CCP driver's handling of PDH export operations.
What input condition triggers the crash?
A PDH export request with a zero-length userspace certificate-chain buffer can trigger the issue. The zero-length allocation produces ZERO_SIZE_PTR, and the vulnerable path attempts to obtain its physical address.
How can I identify this issue in crash logs?
The reported failure is a kernel BUG in __phys_addr at arch/x86/mm/physaddr.c:28, with an invalid-opcode Oops. Logs may also show CONFIG_DEBUG_VIRTUAL-related behavior and a call path involving the CCP PDH export handling.