VDB
CVE-2026-80924
CVE-2026-80924
PUBLISHED
CVSS 7.5 HIGH
Reported by Linux · Published September 9, 2026
In the Linux kernel, the following vulnerability has been resolved: crypto: krb5 - use kfree_sensitive() for derived key buffers crypto_krb5_prepare_encryption() and crypto_krb5_prepare_checksum() free the buffer holding the freshly derived keys with plain kfree(), leaving the key material behind in the freed slab object.
EPSS 0.19% · 9.2th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.19%
9.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | 3936f02bf2d3308a7359dd37dd96cd60603d8170, 3936f02bf2d3308a7359dd37dd96cd60603d8170, 3936f02bf2d3308a7359dd37dd96cd60603d8170 |
| Linux | Linux | 6.15, 0, 6.18.49 |
| linux | linux_kernel | 6.15, 6.15, 6.15 |
| Linux | Linux | 3936f02bf2d3308a7359dd37dd96cd60603d8170, 3936f02bf2d3308a7359dd37dd96cd60603d8170, 3936f02bf2d3308a7359dd37dd96cd60603d8170 |
Timeline
- Sep 9, 2026 Coalition ESS Score
- Sep 9, 2026 CVE Published
- Sep 10, 2026 EPSS Score
- Sep 10, 2026 CVE Updated
- Sep 15, 2026 EPSS Score
- Sep 18, 2026 EPSS Score