CVE-2026-63823 | In the Linux kernel, the following vulnerability has been resolved: keys: Pin request_key_auth payload in instantiate paths A: request_key() B: KEYCTL_INSTANTIATE_IOV ================ ========================= create auth key store rka in auth key wait for helper get auth key load rka from auth key copy user payload sleep on #PF helper completed detach
In the Linux kernel, the following vulnerability has been resolved:
keys: Pin request_key_auth payload in instantiate paths
A: request_key() B: KEYCTL_INSTANTIATE_IOV
================ =========================
create auth key
store rka in auth key
wait for helper
get auth key
load rka from auth key
copy user payload
sleep on #PF
helper completed
detach and free rka
destroy auth key
wake up
use rka->target_key
**USE-AFTER-FREE**
Give request_key_auth payloads a refcount. Take a payload reference while
authkey->sem stabilizes the payload and revocation state. Hold that
reference across the instantiate and reject paths. Drop the auth key
owning reference from revoke and destroy.
[jarkko: Replaced the first two paragraphs of text with an actual
concurrency scenario.]
- 🔗 git.kernel.org/stable/c/d8274181b0f28d450b42489723a5ba81…
- 🔗 git.kernel.org/stable/c/4982bfabce6b33b3c9eddb4fb900fe55…
- 🔗 git.kernel.org/stable/c/708709c65a1832a99b0eef8ae46e343d…
- 🔗 git.kernel.org/stable/c/35ab4db86774d82389e4b9559e26ab7f…
- 🔗 git.kernel.org/stable/c/f9b68632ac93cc742f2e411021c4dbfe…
- 🔗 git.kernel.org/stable/c/7216ce8cb12fee44e309503955bb8380…
- 🔗 git.kernel.org/stable/c/83c0a1cb296d955d5f4d1f0bd8a769ba…
- 🔗 git.kernel.org/stable/c/fd15b457a86939c38aa12116adabd8ff…
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-31 | 2026-09-19 |
|---|---|---|
| ≥90 % | 0 | 538 |
| ≥50 % | 0 | 1603 |
| ≥10 % | 0 | 17 |
| <10 % | 300 | 56400 |
CVE-2026-63823 | In the Linux kernel, the following vulnerability has been resolved: keys: Pin request_key_auth payload in instantiate paths A: request_key() B: KEYCTL_INSTANTIATE_IOV ================ ========================= create auth key store rka in auth key wait for helper get auth key load rka from auth key copy user payload sleep on #PF helper completed detach
In the Linux kernel, the following vulnerability has been resolved: keys: Pin request_key_auth payload in instantiate paths A: request_key() B: KEYCTL_INSTANTIATE_IOV ================ ========================= create auth key