CVE-2026-98221

Source
https://cve.org/CVERecord?id=CVE-2026-98221
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98221.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98221
Downstream
Published
2026-10-06T08:44:56Z
Modified
2026-10-08T02:52:53Z
Summary
KEYS: trusted: Fix tpm2_load_cmd() boundary check
Details

In the Linux kernel, the following vulnerability has been resolved:

KEYS: trusted: Fix tpm2_load_cmd() boundary check

tpm2_load_cmd() does boundary checks against the ASN.1 size i.e., payload->blob_len. Address this by passing the decoded blob size to tpm2_load_cmd(), and use it for the boundary checks.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98221.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
f2219745250f388edacabe6cca73654131c67d0a
Fixed
cc86227fea28aed86c1fb52a884560b4440da198
Fixed
b020b447338872440142fe8a57350a483da86b7a
Fixed
3fd487c69ad3161e358c33c170bab0cf02a071b7
Fixed
5afa57ea91481c6c49f194b0f5a5c4d96a4d7348
Fixed
9ddbc5f4bb498aff8096a5231574858a4bffee4f
Fixed
134825dfc971fbf2b1d0f58f0b3bce8332ad0afb
Fixed
114f00d738f15dd8c7318369edcdc53dd6d08763

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98221.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.13.0
Fixed
5.15.222
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.189
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98221.json"