VDB

CVE-2026-80924

CVE-2026-80924 PUBLISHED CVSS 7.5 HIGH

Reported by Linux · Published September 9, 2026

In the Linux kernel, the following vulnerability has been resolved: crypto: krb5 - use kfree_sensitive() for derived key buffers crypto_krb5_prepare_encryption() and crypto_krb5_prepare_checksum() free the buffer holding the freshly derived keys with plain kfree(), leaving the key material behind in the freed slab object.

EPSS 0.19% · 9.2th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.19%
9.2th percentile

Affected Products

VendorProductVersions
LinuxLinux3936f02bf2d3308a7359dd37dd96cd60603d8170, 3936f02bf2d3308a7359dd37dd96cd60603d8170, 3936f02bf2d3308a7359dd37dd96cd60603d8170
LinuxLinux6.15, 0, 6.18.49
linuxlinux_kernel6.15, 6.15, 6.15
LinuxLinux3936f02bf2d3308a7359dd37dd96cd60603d8170, 3936f02bf2d3308a7359dd37dd96cd60603d8170, 3936f02bf2d3308a7359dd37dd96cd60603d8170

Timeline

  • Sep 9, 2026 Coalition ESS Score
  • Sep 9, 2026 CVE Published
  • Sep 10, 2026 EPSS Score
  • Sep 10, 2026 CVE Updated
  • Sep 15, 2026 EPSS Score
  • Sep 18, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›