CVE-2026-63824

Source
https://cve.org/CVERecord?id=CVE-2026-63824
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63824.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63824
Downstream
Published
2026-07-19T12:02:20.406Z
Modified
2026-07-22T05:30:00.550430870Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
KEYS: fix overflow in keyctl_pkey_params_get_2()
Details

In the Linux kernel, the following vulnerability has been resolved:

KEYS: fix overflow in keyctlpkeyparamsget2()

The length for the internal output buffer is calculated incorrectly, which can result overflow when a too small buffer is provided.

Fix the bug by allocating internal output with the size of the maximum length of the cryptographic primitive instead of caller provided size.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63824.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
00d60fd3b93219ea854220f0fd264b86398cbc53
Fixed
622ec2dcd59f21623f2a7ab773c80ceb7d555e3a
Fixed
b1e247338bc71826a2d2def3e0874c34749df69a
Fixed
0f3058d7d26f81df9b68a18ddbe164bdc3c5eff3
Fixed
5966e4e2ba213ab7ad559166152eb4f1f170dd2c
Fixed
5165f1cc727f1322456735df212d8e26ec237a8d
Fixed
b11c1fa32667692a2c0566e10163758e786e430c
Fixed
670fc6a311ed321522b7fff92cf0fc376b4f6e78
Fixed
cb481e59ea6cae3b7796ac1d7a22b6b24c3f3c0b

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63824.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.20.0
Fixed
5.10.260
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.211
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.177
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.144
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.95
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.38
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63824.json"