CVE-2026-80924

Source
https://cve.org/CVERecord?id=CVE-2026-80924
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80924.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80924
Downstream
Published
2026-09-09T16:19:44Z
Modified
2026-09-10T03:48:25Z
Summary
crypto: krb5 - use kfree_sensitive() for derived key buffers
Details

In the Linux kernel, the following vulnerability has been resolved:

crypto: krb5 - use kfree_sensitive() for derived key buffers

crypto_krb5_prepare_encryption() and crypto_krb5_prepare_checksum() free the buffer holding the freshly derived keys with plain kfree(), leaving the key material behind in the freed slab object.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80924.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
3936f02bf2d3308a7359dd37dd96cd60603d8170
Fixed
731a5b6fb4c1705f9405d9029dd64ea81e336207
Fixed
91b96dc9cc250cd16751f53de525cf3442ca0962
Fixed
a1bf79365794783b19f5b09e8a23f7ee311e8931
Fixed
f7d53dd3f267e46a784f219a75072f2f400d42b9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80924.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.15.0
Fixed
6.18.49
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.13
Type
ECOSYSTEM
Events
Introduced
7.2.0
Fixed
7.2.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80924.json"