CVE-2026-98222

Source
https://cve.org/CVERecord?id=CVE-2026-98222
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98222.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98222
Downstream
Published
2026-10-06T08:44:57Z
Modified
2026-10-08T02:52:54Z
Summary
KEYS: encrypted: fix integer overflow of datablob_len
Details

In the Linux kernel, the following vulnerability has been resolved:

KEYS: encrypted: fix integer overflow of datablob_len

encrypted_key_alloc() stores datablob_len in a u16. It is computed from multiple string and payload lengths. If the result exceeds U16_MAX, the assignment truncates the allocation size. KASAN reports a 32760-byte slab-out-of-bounds write when __ekey_init() copies the master key description into the undersized buffer.

The total payload length stored in key->datalen is also a u16. Use check_add_overflow() to reject values that do not fit either destination, and use kzalloc_flex() for the flexible-array allocation.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98222.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
7e70cb4978507cf31d76b90e4cfb4c28cad87f0c
Fixed
1e720f63dbafc093a8f5d519f05b67724993edd4
Fixed
a1a98eca102b1cbbc37ff9eaa197ae4e6a3ea4b0
Fixed
cca38f2102a4cd35eda8d48950df4817b4b24757
Fixed
8697c431e297eb0d0ab13dda6bc172b48a34f05c

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98222.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.6.38
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98222.json"