Linux Kernel s390/zcrypt EP11 CPRB Domain Limit Bypass
CVE-2026-80709 Published on August 28, 2026
s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs
In the Linux kernel, the following vulnerability has been resolved:
s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs
There is a wrong upper limit check for the domain value when an EP11
CPRB is processed for sending to a crypto card. This check is only
active on custom device nodes but may lead to access heap memory
behind perms->adm when an administrative CPRB is sent.
Add correct limit (AP_DOMAINS = 256) checking to fix this.
Products Associated with CVE-2026-80709
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version cfd68b33094e1a92249850ff3c3c92ae9112a541 and below 4589f742718d0256ea6dd1f5a78be6e689bdb8aa is affected.
- Version cfd68b33094e1a92249850ff3c3c92ae9112a541 and below b505dcc8307d64468b463dfad45a03bf865c637e is affected.
- Version cfd68b33094e1a92249850ff3c3c92ae9112a541 and below 13e53d6ae1c3b2ff1be75b9ef09be26f4ec3ce15 is affected.
- Version cfd68b33094e1a92249850ff3c3c92ae9112a541 and below 672b12940e3f1336dfed5287412a71500adf2a76 is affected.
- Version cfd68b33094e1a92249850ff3c3c92ae9112a541 and below 1223477ca88e2396eca440919d0ca8754df79bd5 is affected.
- Version cfd68b33094e1a92249850ff3c3c92ae9112a541 and below 983279d7f86ade73db86f886e09172dd567031b5 is affected.
- Version 5.18 is affected.
- Before 5.18 is unaffected.
- Version 6.1.183, <= 6.1.* is unaffected.
- Version 6.6.151, <= 6.6.* is unaffected.
- Version 6.12.103, <= 6.12.* is unaffected.
- Version 6.18.44, <= 6.18.* is unaffected.
- Version 7.1.8, <= 7.1.* is unaffected.
- Version 7.2, <= * is unaffected.