Database/Kernel, userspace & hypervisor

Linux kernel trusted keys: TPM2 key load bounds-checks against the wrong blob length
Impact
tpm2_load_cmd() validated the blob against payload->blob_len - the ASN.1 size - rather than the size of the decoded blob, so a crafted trusted-key blob can drive the load past the real buffer. The path is reached from user space through add_key/keyctl with a user-supplied blob on any node that has a TPM2 device in use. This matters on fleets that seal disk, fabric or node-identity secrets to the TPM, since the keyring load path is exercised by unprivileged callers. The record gives no score, no CWE and does not state how far the access goes - treat it as a bounds-check failure of unestablished severity. The fix passes the decoded blob size into the boundary checks.
Who can reach it
Local user able to call add_key with the trusted key type on a node with a TPM2 device. No remote path; the record does not say whether a container tenant can reach it in a typical confined profile.
What to do
Update to a stable kernel carrying the fix (commits linked in the record) and reboot the node; there is no module reload or runtime toggle for this code path. The record names no fixed distribution version - check your vendor's kernel advisory before scheduling.
References
Related entries
- Linux kernel encrypted keys: u16 truncation of datablob_len gives a slab out-of-bounds writeCVE-2026-98222 · Linux kernel KEYS subsystem (encrypted keys, encrypted_key_alloc)Unscored
- Linux kernel SCSI core: unvalidated MODE SENSE lengths leak stack memory to the storage deviceCVE-2026-98232 · Linux kernel SCSI core (scsi_cdl_enable MODE SENSE length validation)Unscored
- Linux kernel dma-buf: 32-bit mapped_len truncates peer-to-peer DMA mappings larger than 4 GiBCVE-2026-98242 · Linux kernel dma-buf (phys vec to scatterlist conversion, mapped_len overflow)Unscored
- Linux kernel dma-fence: lost RCU protection after signalling allows use-after-free of fence name stringsCVE-2026-98243 · Linux kernel dma-buf/dma-fence (timeline and driver name accessors)Unscored
- Linux kernel arm64: LSE percpu ops on 8/16-bit types read and write 32 bits of memoryCVE-2026-98248 · Linux kernel arm64 percpu operations (LSE atomics on 8- and 16-bit types)Unscored
- Linux kernel RDMA/core: iWARP port mapper initialises its refcount after publishing the requestCVE-2026-98252 · Linux kernel RDMA/core iWARP port mapper (iwpm_get_nlmsg_request refcount init)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.