-

CVE-2026-74566

keys: make keyring key-chunk byte order agree with keyring_diff_objects()

In the Linux kernel, the following vulnerability has been resolved:

keys: make keyring key-chunk byte order agree with keyring_diff_objects()

keyring_get_key_chunk() loads description bytes into the index chunk low
address first, while keyring_diff_objects() numbers the first differing
bit from the low end and folds the absolute byte index into the level
without removing the inline-prefix offset the level already carries.
The two disagree on byte order and bit position, so the array can be
told two keys first differ at a bit that does not differ in the chunk
the walker uses, letting crafted descriptions collide into one node.

Load the chunk in the order keyring_diff_objects() assumes and drop the
inline-prefix length when folding the byte index into the level.  This
only changes the in-memory ordering used to place keys within a keyring;
add, search and read of non-colliding keys are unaffected.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version f771fde82051976a6fc0fd570f8b86de4a92124b
Version < 414bcf37d81ce9b3823aabc06b04c97fdcbe489b
Status affected
Version f771fde82051976a6fc0fd570f8b86de4a92124b
Version < abe43c661efb753d5ee35ad8ace4bbb16fa9afd0
Status affected
Version f771fde82051976a6fc0fd570f8b86de4a92124b
Version < f81920917074e3c4ad4fba06fe8c56738d010606
Status affected
Version f771fde82051976a6fc0fd570f8b86de4a92124b
Version < bd0f976ef89dce6db458bf75bc2cf51127becc41
Status affected
Version f771fde82051976a6fc0fd570f8b86de4a92124b
Version < 7269df3e7fcfa308e6a456305162f7788747bdbd
Status affected
Version f771fde82051976a6fc0fd570f8b86de4a92124b
Version < 3d9f16c0b643ceac305526b2e2fe25c2c6166926
Status affected
Version f771fde82051976a6fc0fd570f8b86de4a92124b
Version < 7e5397a3fed0dee7779bd084bec3c0584db3c930
Status affected
Version f771fde82051976a6fc0fd570f8b86de4a92124b
Version < 58565eef0f8d861aae92abfb7658458d661cee17
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.3
Status affected
Version 0
Version < 5.3
Status unaffected
Version <= 5.10.*
Version 5.10.265
Status unaffected
Version <= 5.15.*
Version 5.15.216
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.151
Status unaffected
Version <= 6.12.*
Version 6.12.103
Status unaffected
Version <= 6.18.*
Version 6.18.44
Status unaffected
Version <= 7.1.*
Version 7.1.8
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.062
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/bd0f976ef89dce6db458bf75bc2cf51127becc41
https://git.kernel.org/stable/c/7269df3e7fcfa308e6a456305162f7788747bdbd
https://git.kernel.org/stable/c/3d9f16c0b643ceac305526b2e2fe25c2c6166926
https://git.kernel.org/stable/c/7e5397a3fed0dee7779bd084bec3c0584db3c930
https://git.kernel.org/stable/c/58565eef0f8d861aae92abfb7658458d661cee17
https://git.kernel.org/stable/c/414bcf37d81ce9b3823aabc06b04c97fdcbe489b
https://git.kernel.org/stable/c/abe43c661efb753d5ee35ad8ace4bbb16fa9afd0
https://git.kernel.org/stable/c/f81920917074e3c4ad4fba06fe8c56738d010606