In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2protkey Add validation of both the actual key buffer size and token length fields…
高危 CVSS 7.1
摘要
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2protkey Add validation of both the actual key buffer size and token length fields in all the cca_check_sec*token() functions. Additionally check in cca_gencipherkey() for possible underflow with returned key size. The CCA token structures contain user-controlled len fields that were used in operations without proper validation against both the actual buffer size and minimum tok…
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
数据来源
- NVD DATABASE
原始链接
- https://git.kernel.org/stable/c/36b230835b8a008266aad22168ca52afacc8a58d
- https://git.kernel.org/stable/c/3b2abee2a678607ae27975bc6833785c2002df43
- https://git.kernel.org/stable/c/a57fd7fcdb63e2d5ceac78bbe825ec986062a9da
时间线
- nvd_ingest NVD