CVE-2026-74466: s390/zcrypt: Close speculative mem read possibility
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026081533-CVE-2026-74466-e525@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Close speculative mem read possibility The domain value is extracted from a given CCA or EP11 ioctl struct when a CPRB is about to be sent. Thus this is a user controlled value. Under some special conditions (custom device node used, administrative load) this value is used as an array index after bounds checking, but without speculation barrier. Add the missing array_index_nospec() call to prevent speculative execution where this domain value is used. The Linux kernel CVE team has assigned CVE-2026-74466 to this issue. Affected and fixed versions =========================== Issue introduced in 5.18 with commit cfd68b33094e1a92249850ff3c3c92ae9112a541 and fixed in 7.1.8 with commit 82b62eda68abfb7a33ac40f24b8c4128c2891148 Issue introduced in 5.18 with commit cfd68b33094e1a92249850ff3c3c92ae9112a541 and fixed in 7.2-rc6 with commit e935cd525af4c6ed2e2c6404aa27ca19c7f39ddb Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-74466 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/s390/crypto/zcrypt_api.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/82b62eda68abfb7a33ac40f24b8c4128c2891148 https://git.kernel.org/stable/c/e935cd525af4c6ed2e2c6404aa27ca19c7f39ddb