7.8
CVE-2026-68147
- EPSS 0.14%
- Veröffentlicht 10.08.2026 11:59:12
- Zuletzt bearbeitet 19.08.2026 17:20:31
- Erkennungen
fscrypt: Avoid dynamic allocation in fscrypt_get_devices()
In the Linux kernel, the following vulnerability has been resolved: fscrypt: Avoid dynamic allocation in fscrypt_get_devices() When a blk_crypto_key starts being used or is evicted, fs/crypto/ calls fscrypt_get_devices() to get the filesystem's list of block devices, then iterates over them and calls blk_crypto_config_supported(), blk_crypto_start_using_key(), or blk_crypto_evict_key() on each one. Currently, the block device pointers are placed in a dynamically allocated array. This dynamic allocation is problematic because: - It can fail, especially at the fscrypt_destroy_inline_crypt_key() call site when it's invoked for inode eviction under direct reclaim. - fscrypt_destroy_inline_crypt_key() doesn't handle the failure. It just zeroizes and frees the blk_crypto_key without calling blk_crypto_evict_key(). That causes a use-after-free. For now, let's fix this in the straightforward and easily-backportable way by switching to an on-stack array. Currently the fscrypt multi-device functionality is used only by f2fs, which has a hardcoded limit of 8 block devices. An on-stack array works fine for that. (Of course, this solution won't scale up to large number of block devices. For that we'd need a different solution, like moving the block device iteration into the filesystem. Or in the case of btrfs, which will only support blk-crypto-fallback, we should make it just call blk-crypto-fallback directly, so the block devices won't be needed.)
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
22e9947a4b2ba255888541bd0111cf00b9b16586
Version <
bab016bb80d74a9d1f7d4121a7fc1cb529b470e0
Status
affected
Version
22e9947a4b2ba255888541bd0111cf00b9b16586
Version <
4462ac3d90e897dda52ce4b6af2d526ddae835a8
Status
affected
Version
22e9947a4b2ba255888541bd0111cf00b9b16586
Version <
97a688563be71ec6fefc071aff69a66c69dbe244
Status
affected
Version
22e9947a4b2ba255888541bd0111cf00b9b16586
Version <
81ea8e8221853950c47dac7164f27c63a96f8f86
Status
affected
Version
22e9947a4b2ba255888541bd0111cf00b9b16586
Version <
bc2d630296e0e049210ec05ff08459a6893ae749
Status
affected
Version
22e9947a4b2ba255888541bd0111cf00b9b16586
Version <
6fe4e4b8259e1330945b5f3c9476e08473b8e0e8
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
6.1
Status
affected
Version
0
Version <
6.1
Status
unaffected
Version <=
6.1.*
Version
6.1.183
Status
unaffected
Version <=
6.6.*
Version
6.6.148
Status
unaffected
Version <=
6.12.*
Version
6.12.101
Status
unaffected
Version <=
6.18.*
Version
6.18.42
Status
unaffected
Version <=
7.1.*
Version
7.1.6
Status
unaffected
Version <=
*
Version
7.2
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.14% | 0.034 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
https://git.kernel.org/stable/c/4462ac3d90e897dda52ce4b6af2d526ddae835a8
https://git.kernel.org/stable/c/97a688563be71ec6fefc071aff69a66c69dbe244
https://git.kernel.org/stable/c/81ea8e8221853950c47dac7164f27c63a96f8f86
https://git.kernel.org/stable/c/bc2d630296e0e049210ec05ff08459a6893ae749
https://git.kernel.org/stable/c/6fe4e4b8259e1330945b5f3c9476e08473b8e0e8
https://git.kernel.org/stable/c/bab016bb80d74a9d1f7d4121a7fc1cb529b470e0