s390/zcrypt: Validate length for CCA AES cipher key requests
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 7.8epss 0.1%
probabilidade de exploração
0.1%top 97% das CVEs
exploração observada
nãonenhuma fonte reporta
In the Linux kernel, the following vulnerability has been resolved:
s390/zcrypt: Validate length for CCA AES cipher key requests
cca_cipher2protkey() derives the copy length for the CPRB parameter
block directly from the length field in the key token. Reject the
request early if the token length exceeds the available space in the
parameter block.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
Linux · LinuxReferências
https://git.kernel.org/stable/c/06afe425d5283b9764303de47f554da5a808ce8ahttps://git.kernel.org/stable/c/3859f630b674801a00bca39bc451f52288591f65https://git.kernel.org/stable/c/406b317ea2b501f6f5eca1264293c9399a73a778https://git.kernel.org/stable/c/4e500ecb6704d879f9c2417c2ed6faba595015cahttps://git.kernel.org/stable/c/4fc46deceda076d429ef3fab2ccf8d96629ebd23https://git.kernel.org/stable/c/7f9e5a3dbb14a9b321a1dfa30390402c673f82dchttps://git.kernel.org/stable/c/ad93a1f1a45652478c0cf4eb029114e03af57f3bhttps://git.kernel.org/stable/c/be037204e4f595e4bd2159acda146677a1dc6342