GPU VulnDB

Database/Kernel, userspace & hypervisor

Linux kernel trusted keys: TPM2 key load bounds-checks against the wrong blob length

UnscoredCVE-2026-98221Kernel, userspace & hypervisorcurated

Impact

tpm2_load_cmd() validated the blob against payload->blob_len - the ASN.1 size - rather than the size of the decoded blob, so a crafted trusted-key blob can drive the load past the real buffer. The path is reached from user space through add_key/keyctl with a user-supplied blob on any node that has a TPM2 device in use. This matters on fleets that seal disk, fabric or node-identity secrets to the TPM, since the keyring load path is exercised by unprivileged callers. The record gives no score, no CWE and does not state how far the access goes - treat it as a bounds-check failure of unestablished severity. The fix passes the decoded blob size into the boundary checks.

Who can reach it

Local user able to call add_key with the trusted key type on a node with a TPM2 device. No remote path; the record does not say whether a container tenant can reach it in a typical confined profile.

What to do

Update to a stable kernel carrying the fix (commits linked in the record) and reboot the node; there is no module reload or runtime toggle for this code path. The record names no fixed distribution version - check your vendor's kernel advisory before scheduling.

References

Related entries

All Kernel, userspace & hypervisor entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.