CVE-2026-68452
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Validate length for CCA AES cipher key requests cca_cipher2protkey() derives the copy length for the CPRB parameter block directly from the length field in the key token. Reject the request early if the token length exceeds the available space in the parameter block.
- Affected products
- Kernel, Linux, Linux-Allwinner-5.19, Linux-Aws, Linux-Aws-5.0, Linux-Aws-5.11, Linux-Aws-5.13, Linux-Aws-5.15
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 0.1% (3th percentile)
- NVD status
- Received
- Published
- 2026-08-13
CVE-2026-68452 at NVD
No indexed exploits for CVE-2026-68452 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-68452 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.