In the Linux kernel, the following vulnerability has been resolved:
KEYS: fix overflow in keyctlpkeyparamsget2()
The length for the internal output buffer is calculated incorrectly, which can result overflow when a too small buffer is provided.
Fix the bug by allocating internal output with the size of the maximum length of the cryptographic primitive instead of caller provided size.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63824.json",
"cna_assigner": "Linux"
}