Answer in brief
CVE-2026-98222 records a Unknown severity vulnerability in KEYS: encrypted: fix integer overflow of datablob_len. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=7e70cb4978507cf31d76b90e4cfb4c28cad87f0c <1e720f63dbafc093a8f5d519f05b67724993edd4 || >=7e70cb4978507cf31d76b90e4cfb4c28cad87f0c <a1a98eca102b1cbbc37ff9eaa197ae4e6a3ea4b0 || >=7e70cb4978507cf31d76b90e4cfb4c28cad87f0c <cca38f2102a4cd35eda8d48950df4817b4b24757 || >=7e70cb4978507cf31d76b90e4cfb4c28cad87f0c <8697c431e297eb0d0ab13dda6bc172b48a34f05c | 1e720f63dbafc093a8f5d519f05b67724993edd4, a1a98eca102b1cbbc37ff9eaa197ae4e6a3ea4b0, cca38f2102a4cd35eda8d48950df4817b4b24757, 8697c431e297eb0d0ab13dda6bc172b48a34f05c |
| Linux/Linuxgeneric | 2.6.38 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: KEYS: encrypted: fix integer overflow of datablob_len encrypted_key_alloc() stores datablob_len in a u16. It is computed from multiple string and payload lengths. If the result exceeds U16_MAX, the assignment truncates the allocation size. KASAN reports a 32760-byte slab-out-of-bounds write when __ekey_init() copies the master key description into the undersized buffer. The total payload length stored in key->datalen is also a u16. Use check_add_overflow() to reject values that do not fit either destination, and use kzalloc_flex() for the flexible-array allocation.
Quoted source text, attributed separately from HOL analysis.