CVE-2026-64558
Linux Kernel Schwachstellenanalyse und -minderung

Überblick

CVE-2026-64558 is a Linux kernel vulnerability in the s390/pkey subsystem where the pkey_pckmo handler implementation of the key_to_protkey() function fails to explicitly validate the length of the target buffer before writing output data. If the generated output data exceeds the provided target buffer length, the handler function fails, potentially leading to an out-of-bounds write condition (CWE-787). The vulnerability affects Linux kernel versions starting from commit 8fcc231ce3bea12b78bb94b280cdc03cff342435 through the 6.12 and 6.18 stable series. It was published on July 29, 2026, and carries a CVSS v3.1 base score of 7.8 (High) (Github Advisory, Red Hat).

Technische Details

The root cause is an out-of-bounds write (CWE-787) in the pkey_pckmo handler within the Linux kernel's s390 protected key (pkey) subsystem. The key_to_protkey() handler function does not check whether the size of the generated output data fits within the caller-supplied target buffer before writing, allowing a write beyond the buffer boundary if the output is larger than expected. Exploitation requires local access with low privileges — specifically, the ability to invoke pkey subsystem operations — and no user interaction. No public proof-of-concept exploit code has been identified (Github Advisory, Red Hat).

Aufprall

Successful exploitation could result in high impacts to confidentiality, integrity, and availability on the affected system, as reflected in the CVSS scoring. A local attacker with low privileges could trigger an out-of-bounds write in kernel memory, potentially corrupting kernel data structures, causing a kernel panic (denial of service), or in more severe scenarios, escalating privileges or leaking sensitive cryptographic key material handled by the pkey subsystem. The vulnerability is scoped to the local system and does not directly enable lateral movement, but kernel-level compromise could facilitate further post-exploitation activity (Github Advisory, Red Hat).

Risikominderung und Problemumgehungen

Patches have been committed to the Linux kernel stable trees. Fixed versions include kernel 6.12.97 (for the 6.12.x series), 6.18.40 (for the 6.18.x series), 7.1.5 (for the 7.1.x series), and 7.2-rc1 and later. Administrators should update to the appropriate patched kernel version for their distribution. As a workaround, restricting access to pkey subsystem operations to only authorized users can reduce exposure until a patch is applied (Github Advisory, Red Hat).

Zusätzliche Ressourcen


QuelleDieser Bericht wurde mithilfe von KI erstellt

Verwandt Linux Kernel Schwachstellen:

CVE-Kennung

Strenge

Punktzahl

Technologieen

Name der Komponente

CISA KEV-Exploit

Hat fix

Veröffentlichungsdatum

CVE-2026-64557HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-riscv-6.17
NeinJaJul 29, 2026
CVE-2026-64560HIGH7.8
  • Linux Kernel logoLinux Kernel
  • kernel-64k-debug-core
NeinJaJul 29, 2026
CVE-2026-64559HIGH7.8
  • Linux Kernel logoLinux Kernel
  • kernel-doc
NeinJaJul 29, 2026
CVE-2026-64558HIGH7.8
  • Linux Kernel logoLinux Kernel
  • kernel-rt-debug-modules
NeinJaJul 29, 2026
CVE-2022-4994NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-nvidia
NeinJaJul 30, 2026

Kostenlose Schwachstellenbewertung

Benchmarking Ihrer Cloud-Sicherheitslage

Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.

Bewertung anfordern

Eine personalisierte Demo anfordern

Sind Sie bereit, Wiz in Aktion zu sehen?

"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
David EstlickCISO
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
Adam FletcherSicherheitsbeauftragter
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"
Greg PoniatowskiLeiter Bedrohungs- und Schwachstellenmanagement