CVE-2026-31746

Source
https://cve.org/CVERecord?id=CVE-2026-31746
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-31746.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-31746
Downstream
Published
2026-05-01T14:14:40.196Z
Modified
2026-08-12T03:51:30.265357247Z
Summary
s390/zcrypt: Fix memory leak with CCA cards used as accelerator
Details

In the Linux kernel, the following vulnerability has been resolved:

s390/zcrypt: Fix memory leak with CCA cards used as accelerator

Tests showed that there is a memory leak if CCA cards are used as accelerator for clear key RSA requests (ME and CRT). With the last rework for the memory allocation the AP messages are allocated by apinitapmsg() but for some reason on two places (ME and CRT) the older allocation was still in place. So the first allocation simple was never freed.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31746.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
57db62a130ce69e6f3a870cf1119d8f860391f97
Fixed
586222c37d4027dbf60a604fbe820184fee7c1c9
Fixed
ace37bfec3822033e59fff390f2ff99fc96ebe4f
Fixed
c8d46f17c2fc7d25c18e60c008928aecab26184d

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-31746.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.16.0
Fixed
6.18.22
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
6.19.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-31746.json"