Executive brief
A vulnerability in the Linux kernel's cryptographic component could allow a local user to access sensitive information from the system's memory. This occurs when the system attempts to retrieve a unique identifier for the processor and fails to handle errors correctly. An attacker could exploit this to leak data or cause a system crash, potentially impacting the confidentiality of system operations.
Technical details
An out-of-bounds write/read vulnerability (CWE-787) exists in the Linux kernel's 'crypto: ccp' driver within the 'sev_ioctl_do_get_id2' function. When the Platform Security Processor (PSP) firmware command fails—specifically due to an invalid buffer length provided by userspace—the driver incorrectly proceeds to copy data back to userspace using the length required by the firmware rather than the length allocated for the buffer. This results in a slab-out-of-bounds access that can leak kernel memory to userspace or cause a kernel panic (KASAN detected). The issue is triggered via a local IOCTL call and has been patched in multiple stable branches including 6.6.y, 6.12.y, 6.18.y, and 7.0.y.
Affected products
- Linux Linux Kernel 5.2 to 6.6.136, 6.7 to 6.12.84, 6.13 to 6.18.25, 6.19 to 7.0.2
Timeline
- 2026-03-13: other: Patch authored
- 2026-05-01: disclosed: CVE published
References
- https://git.kernel.org/stable/c/06f06d88c05ce176c61fff8c72c372847b0dd2b5
- https://git.kernel.org/stable/c/09427bcb1715fb20a80b6acd5156dbf15ab5c363
- https://git.kernel.org/stable/c/0f1f2f9894893dc8a28af1b9e9dbc0abf453eb52
- https://git.kernel.org/stable/c/1fbac0429a42adec830491757a2b53956dd797ea
- https://git.kernel.org/stable/c/2937f17bbeefb8e7608ff1f78cffbeb3d0281e5e
- https://git.kernel.org/stable/c/4f685dbfa87c546e51d9dc6cab379d20f275e114
- https://git.kernel.org/stable/c/99bae2e3c3f9ba8f854c938ed2c811b6a63b28e4