Security Advisory

CVE-2026-63824

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-19 12:02:20
Last updated 2026-07-20 13:40:28
Assigner Linux
CVSS score 7.8
State PUBLISHED

Description

In the Linux kernel, the following vulnerability has been resolved: KEYS: fix overflow in keyctl_pkey_params_get_2() The length for the internal output buffer is calculated incorrectly, which can result overflow when a too small buffer is provided. Fix the bug by allocating internal output with the size of the maximum length of the cryptographic primitive instead of caller provided size.