Database/Kernel, userspace & hypervisor
Linux kernel keyrings: out-of-bounds read in keyring_get_key_chunk() from unprivileged add_key(2)
Impact
For description-level chunks the keyring assoc-array walk advances the read pointer by level * sizeof(long) past the inline prefix but only bounds-checks the prefix, so a long enough key description is read past its kmemdup allocation — KASAN reports a slab out-of-bounds read. Reaching the description level requires two keys of the same type whose index hashes collide, which an attacker constructs deliberately, and the whole sequence runs from plain unprivileged add_key(2) with no capability required. On a shared GPU node that means any tenant with code execution can read adjacent slab memory or crash the host kernel, and the keyring subsystem is compiled into essentially every distribution kernel, so there is no configuration that opts out. The record rates confidentiality and availability high, locally.
Who can reach it
Local unprivileged user calling add_key(2) with a crafted pair of same-type keys — including a tenant inside a container, since add_key is not blocked by default seccomp profiles in every runtime. No authentication beyond code execution on the node.
What to do
Install a stable kernel carrying the fix and reboot each node; the patch is upstream on several branches (commits linked) and there is no configuration toggle that disables the keyring subsystem as a workaround. Plan a drain-and-reboot pass across the fleet rather than a mitigation, and prioritize nodes that hand untrusted tenants shell access.
References
Related entries
- Linux kernel CXL: oversized header-log size overruns the RAS iomap and leaks kernel stack via tracefsCVE-2026-80662 · Linux kernel CXL RAS capability handling (CXL_HEADERLOG_SIZE, header_log_copy and CPER trace path)High
- Linux kernel KVM arm64 NV: unresolvable VNCR translation crashes the host instead of injecting an abortCVE-2026-80665 · Linux kernel KVM/arm64 nested virtualization (kvm_translate_vncr VNCR abort path)High
- Linux kernel mm: snapshot_page() reads a non-existent tail page for order-1 folios and oopses the hostCVE-2026-80685 · Linux kernel mm/util snapshot_page() (order-1 folio tail-page read)High
- Linux kernel cxl/ras: RCH AER capability copy reads past the mapped register blockCVE-2026-89731 · Linux kernel CXL RAS (cxl_rch_get_aer_info, RCRB AER register copy)High
- KVM arm64 vgic-its: guest MAPC with V=0 crashes the host when the VMM saves ITS tablesCVE-2026-89912 · Linux kernel KVM arm64 vgic-its (ITT save path)High
- KVM x86 Hyper-V stimer: overflowed deadline livelocks the vCPU thread and stalls RCU on the hostCVE-2026-89927 · Linux kernel KVM x86 Hyper-V synthetic timer (stimer deadline calculation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.