CVE-2026-98222: KEYS: encrypted: fix integer overflow of datablob_len
In the Linux kernel, the following vulnerability has been resolved:
KEYS: encrypted: fix integer overflow of databloblen
encryptedkeyalloc() stores databloblen in a u16. It is computed from multiple string and payload lengths. If the result exceeds U16MAX, the assignment truncates the allocation size. KASAN reports a 32760-byte slab-out-of-bounds write when ekeyinit() copies the master key description into the undersized buffer.
The total payload length stored in key->datalen is also a u16. Use checkaddoverflow() to reject values that do not fit either destination, and use kzallocflex() for the flexible-array allocation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
In encrypted_key_alloc(), use check_add_overflow() to reject payload lengths that do not fit the u16 datablob_len and key->datalen destinations, and use kzalloc_flex() for the flexible-array allocation to prevent undersized buffers.