Answer in brief
CVE-2026-68453 records a Unknown severity vulnerability in s390/zcrypt: Fix buffer over-read in cca_cipher2protkey. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd <a57fd7fcdb63e2d5ceac78bbe825ec986062a9da || >=4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd <3b2abee2a678607ae27975bc6833785c2002df43 || >=4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd <36b230835b8a008266aad22168ca52afacc8a58d | a57fd7fcdb63e2d5ceac78bbe825ec986062a9da, 3b2abee2a678607ae27975bc6833785c2002df43, 36b230835b8a008266aad22168ca52afacc8a58d |
| Linux/Linuxgeneric | 5.4 | Not reported |
Published upstream
Aug 13, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 13, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 13, 2026
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2protkey Add validation of both the actual key buffer size and token length fields in all the cca_check_sec*token() functions. Additionally check in cca_gencipherkey() for possible underflow with returned key size. The CCA token structures contain user-controlled len fields that were used in operations without proper validation against both the actual buffer size and minimum token structure size. An attacker could set this field larger than the actual buffer size, leading to reading beyond buffer boundaries. This may result in a kernel crash or exposure of memory via sending this as part of a request down to the crypto card. Also an attacker could have used a very small len value and thus enforce a buffer under-run which may produce similar effects as a over-read. So now a key must - key buf length must be at least sizeof the token struct - the key len field inside the token must fit into the range of sizeof key token struct ... key buf length
Quoted source text, attributed separately from HOL analysis.
Answer in brief
CVE-2026-68453 records a Unknown severity vulnerability in s390/zcrypt: Fix buffer over-read in cca_cipher2protkey. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd <a57fd7fcdb63e2d5ceac78bbe825ec986062a9da || >=4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd <3b2abee2a678607ae27975bc6833785c2002df43 || >=4bc123b18ce6ae6c42c69d0456b5acbd2f7bc8bd <36b230835b8a008266aad22168ca52afacc8a58d | a57fd7fcdb63e2d5ceac78bbe825ec986062a9da, 3b2abee2a678607ae27975bc6833785c2002df43, 36b230835b8a008266aad22168ca52afacc8a58d |
| Linux/Linuxgeneric | 5.4 | Not reported |
Published upstream
Aug 13, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 13, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 13, 2026
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer over-read in cca_cipher2protkey Add validation of both the actual key buffer size and token length fields in all the cca_check_sec*token() functions. Additionally check in cca_gencipherkey() for possible underflow with returned key size. The CCA token structures contain user-controlled len fields that were used in operations without proper validation against both the actual buffer size and minimum token structure size. An attacker could set this field larger than the actual buffer size, leading to reading beyond buffer boundaries. This may result in a kernel crash or exposure of memory via sending this as part of a request down to the crypto card. Also an attacker could have used a very small len value and thus enforce a buffer under-run which may produce similar effects as a over-read. So now a key must - key buf length must be at least sizeof the token struct - the key len field inside the token must fit into the range of sizeof key token struct ... key buf length
Quoted source text, attributed separately from HOL analysis.