Description
In the Linux kernel, the following vulnerability has been resolved:

crypto: krb5 - use kfree_sensitive() for derived key buffers

crypto_krb5_prepare_encryption() and crypto_krb5_prepare_checksum()
free the buffer holding the freshly derived keys with plain kfree(),
leaving the key material behind in the freed slab object.
Published: 2026-09-09
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Leak of cryptographic key material from kernel buffers
Action: Patch Immediately
AI Analysis

Impact

A flaw in the Linux kernel’s Kerberos (krb5) cryptographic subsystem causes freshly derived key buffers to be freed with a generic kfree() call. Because the kernel does not zero out the memory before deallocating it, the raw key material remains intact in the freed slab object. If an attacker can read kernel memory after the buffer is freed, the sensitive cryptographic keys could be recovered, potentially allowing cryptographic operations to be bypassed or decrypted. This vulnerability directly leads to exposure of confidential information that is not supposed to be recoverable after use. The weakness is a classic misuse of memory deallocation for sensitive data, representing a serious security defect in the kernel’s handling of key material.

Affected Systems

The issue affects the Linux kernel across all supported distributions. Any system running a kernel version that implements the krb5 prepare encryption and checksum functions without the official patch is vulnerable. The problem applies universally, regardless of the specific distribution name, as the underlying kernel code is identical.

Risk and Exploitability

The CVSS score is 7.5, indicating a high severity impact. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits yet. The likely attack vector is a local or privilege‑escalated attacker with access to read kernel memory after the buffer is freed, possibly through another kernel vulnerability or misconfigured privileged service. The impact depends on the attacker’s ability to read the freed slab, which is a non‑trivial loopback scenario but still a severe risk for systems running sensitive Kerberos services.

Generated by OpenCVE AI on September 10, 2026 at 07:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a released version that includes the kfree_sensitive() patch for krb5 derived key buffers.
  • If an immediate kernel upgrade is not feasible, restrict access to Kerberos and related cryptographic services to minimise the number of users with the ability to trigger key derivation, and consider disabling or remapping kernel memory read capabilities for non‑root processes.
  • Regularly audit kernel configuration and check for the presence of the patch commit (e.g., via git log) to confirm the vulnerability has been fixed.

Generated by OpenCVE AI on September 10, 2026 at 07:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Wed, 09 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-241

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: crypto: krb5 - use kfree_sensitive() for derived key buffers crypto_krb5_prepare_encryption() and crypto_krb5_prepare_checksum() free the buffer holding the freshly derived keys with plain kfree(), leaving the key material behind in the freed slab object.
Title crypto: krb5 - use kfree_sensitive() for derived key buffers
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-10T05:50:23.589Z

Reserved: 2026-08-26T14:34:25.802Z

Link: CVE-2026-80924

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T17:17:47.653

Modified: 2026-09-10T06:17:06.213

Link: CVE-2026-80924

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T16:15:05Z

Weaknesses
  • CWE-241

    Improper Handling of Unexpected Data Type