Impact
An internal buffer used by the s390/zcrypt kernel module to build and process command request blocks was not scrubbed after a clear‑key import, allowing the residual clear key material to remain in memory; an attacker who can read kernel memory could recover cryptographic secrets and compromise the confidentiality of protected data, a failure to protect temporary storage (CWE-212).
Affected Systems
The vulnerability exists in Linux kernels executing on the s390 architecture that include the zcrypt clear‑key import code; any installation running a pre‑patch kernel with this module is potentially affected, regardless of specific version details provided in the CNA data.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while the EPSS score of less than 1 % suggests that exploitation is unlikely. The flaw requires local or privileged kernel access and provides no network propagation vector, so the threat is confined to the host running the vulnerable kernel and is not currently listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA