Linux kernel: keyring_get_key_chunk OOB read via crafted add_key
CVE-2026-74567 Published on August 15, 2026
keys: fix out-of-bounds read in keyring_get_key_chunk()
In the Linux kernel, the following vulnerability has been resolved:
keys: fix out-of-bounds read in keyring_get_key_chunk()
For description-level chunks keyring_get_key_chunk() advances the read
pointer by level * sizeof(long) past the inline prefix but only
bounds-checks the prefix, so a long enough key description is read past
its kmemdup(desc, desc_len + 1) allocation. Compute the full byte
offset and bounds-check the description against it before reading.
The walk only reaches a description-level chunk when two keys collide
through the hash, x, type and domain_tag chunks, so this is reached from
an unprivileged add_key(2) with a crafted pair of same-type keys whose
index hashes collide; KASAN reports a slab-out-of-bounds read.
Products Associated with CVE-2026-74567
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version f771fde82051976a6fc0fd570f8b86de4a92124b and below d1933e03e8c74a018550c31a393b79c4d95bff40 is affected.
- Version f771fde82051976a6fc0fd570f8b86de4a92124b and below 3a744838453fb9309ce5a5526d3252e211d60152 is affected.
- Version f771fde82051976a6fc0fd570f8b86de4a92124b and below e9417d21a22ad2ec398e78fcf084b717ce92cf2f is affected.
- Version f771fde82051976a6fc0fd570f8b86de4a92124b and below 8dba33c1e779d0fb9a2acb31e354cf0fc0229111 is affected.
- Version f771fde82051976a6fc0fd570f8b86de4a92124b and below 63918731f9ae25b5deb022f118e941e6dddfcef4 is affected.
- Version 5.3 is affected.
- Before 5.3 is unaffected.
- Version 6.6.151, <= 6.6.* is unaffected.
- Version 6.12.103, <= 6.12.* is unaffected.
- Version 6.18.44, <= 6.18.* is unaffected.
- Version 7.1.8, <= 7.1.* is unaffected.
- Version 7.2-rc6, <= * is unaffected.