{"id":"CVE-2026-68451","summary":"s390/zcrypt: Validate length for CCA ECC private key requests","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ns390/zcrypt: Validate length for CCA ECC private key requests\n\ncca_ecc2protkey() derives the copy length for the CPRB parameter\nblock directly from the length field in the key token. Reject the\nrequest early if the token length exceeds the available space in the\nparameter block.","modified":"2026-08-15T11:47:15.506617254Z","published":"2026-08-13T13:59:53.674Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68451.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/013a4484f061a2b41f052e25c0015203287e63f1"},{"type":"WEB","url":"https://git.kernel.org/stable/c/8fa3e9435a13c335efb63fb4f4e77531a0031159"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a9ae0f6dd45c3ccc1d69363f7aea8af179122730"},{"type":"WEB","url":"https://git.kernel.org/stable/c/dd25bd9b0f36849808bd7625dcc59dd4c1aeef3e"},{"type":"WEB","url":"https://git.kernel.org/stable/c/ecc3b8691c1935f9f3e4eb964ab11e40fdec17f5"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/68xxx/CVE-2026-68451.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-68451"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"fa6999e326fe7851ecbd572b8cb9be8e930ebf41"},{"fixed":"dd25bd9b0f36849808bd7625dcc59dd4c1aeef3e"},{"fixed":"ecc3b8691c1935f9f3e4eb964ab11e40fdec17f5"},{"fixed":"013a4484f061a2b41f052e25c0015203287e63f1"},{"fixed":"8fa3e9435a13c335efb63fb4f4e77531a0031159"},{"fixed":"a9ae0f6dd45c3ccc1d69363f7aea8af179122730"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68451.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.10.0"},{"fixed":"6.6.151"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.103"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.44"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-68451.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}