Executive brief
The Linux kernel's key management subsystem contains a memory bounds-checking bug in the keyring lookup function. An unprivileged user can trigger this flaw by creating two cryptographic keys with specially crafted descriptions that hash to the same value, causing the kernel to read past the end of an allocated memory buffer. This can leak sensitive kernel memory or cause a system crash.
Technical details
The vulnerability is an out-of-bounds read in the keyring_get_key_chunk() function in security/keys/keyring.c. When processing description-level chunks during keyring search, the function advances a read pointer by level * sizeof(long) bytes but only bounds-checks against the inline prefix size, allowing reads past the end of a kmemdup(desc, desc_len + 1) allocation. The flaw occurs only when two keys collide through multiple hash chunks (hash, x, type, and domain_tag), which an unprivileged attacker can trigger via add_key(2) with crafted same-type keys. KASAN detects this as a slab-out-of-bounds read. The fix adds an offset calculation that includes the level multiplication before bounds-checking and adjusts pointer arithmetic accordingly. A patch is available in the Linux stable kernel trees.
Affected products
- Linux Linux kernel multiple versions (2.6.11 through 7.1+)
Timeline
- 2026-08-15: disclosed
- 2026-08-09: patched