CVE-2026-64559
Linux Kernel Schwachstellenanalyse und -minderung

Überblick

CVE-2026-64559 is a buffer access vulnerability in the Linux kernel's s390/pkey subsystem, specifically in the PKEY_VERIFYPROTK ioctl handler, which fails to validate the buffer length parameter supplied by user-space. This allows a local attacker with low privileges to trigger an out-of-bounds buffer access, potentially causing a kernel crash or memory corruption. The vulnerability was published on July 29, 2026, and affects Linux kernel versions starting from commit 8fcc231ce3bea12b78bb94b280cdc03cff342435 through multiple stable branches. It carries a CVSS v3.1 base score of 7.8 (High) (GitHub Advisory, Red Hat Bugzilla).

Technische Details

The root cause is classified as CWE-805 (Buffer Access with Incorrect Length Value): the PKEY_VERIFYPROTK ioctl handler in the s390/pkey subsystem processes a user-supplied buffer length without first verifying that it does not exceed the actual allocated buffer size. An attacker with local access can craft an ioctl request specifying an oversized length value, causing the kernel to access memory beyond the intended buffer boundary. Exploitation requires only low privileges (e.g., a standard user account with access to the pkey ioctl interface) and no user interaction. No public proof-of-concept code has been identified at this time (GitHub Advisory, Red Hat Bugzilla).

Aufprall

Successful exploitation can result in a kernel crash (denial of service) or kernel memory corruption, which may further enable privilege escalation or information disclosure on affected IBM s390/z-series systems running vulnerable Linux kernel versions. The confidentiality, integrity, and availability impacts are all rated High, reflecting the potential for an attacker to read sensitive kernel memory, corrupt kernel data structures, or crash the system entirely. The scope is limited to the local system, but kernel-level memory corruption could facilitate further lateral movement within a multi-tenant or containerized environment (GitHub Advisory).

Risikominderung und Problemumgehungen

Patches have been released for the affected stable kernel branches: version 6.12.97 (for the 6.12.x series), 6.18.40 (for the 6.18.x series), 7.1.5 (for the 7.1.x series), and 7.2-rc1 for the mainline. Administrators should update to one of these patched versions as soon as possible. As a temporary workaround where immediate patching is not feasible, restrict user access to the pkey ioctl interface through system access controls and user privilege restrictions (GitHub Advisory, Red Hat Bugzilla).

Zusätzliche Ressourcen


QuelleDieser Bericht wurde mithilfe von KI erstellt

Verwandt Linux Kernel Schwachstellen:

CVE-Kennung

Strenge

Punktzahl

Technologieen

Name der Komponente

CISA KEV-Exploit

Hat fix

Veröffentlichungsdatum

CVE-2026-64557HIGH8.8
  • Linux Kernel logoLinux Kernel
  • linux-riscv-6.17
NeinJaJul 29, 2026
CVE-2026-64560HIGH7.8
  • Linux Kernel logoLinux Kernel
  • kernel-64k-debug-core
NeinJaJul 29, 2026
CVE-2026-64559HIGH7.8
  • Linux Kernel logoLinux Kernel
  • kernel-doc
NeinJaJul 29, 2026
CVE-2026-64558HIGH7.8
  • Linux Kernel logoLinux Kernel
  • kernel-rt-debug-modules
NeinJaJul 29, 2026
CVE-2022-4994NONEN/A
  • Linux Kernel logoLinux Kernel
  • linux-nvidia
NeinJaJul 30, 2026

Kostenlose Schwachstellenbewertung

Benchmarking Ihrer Cloud-Sicherheitslage

Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.

Bewertung anfordern

Eine personalisierte Demo anfordern

Sind Sie bereit, Wiz in Aktion zu sehen?

"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
David EstlickCISO
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
Adam FletcherSicherheitsbeauftragter
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"
Greg PoniatowskiLeiter Bedrohungs- und Schwachstellenmanagement