← All Advisories

CVE-2026-97592

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97592

Key Details

CVECVE-2026-97592
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

s390/crypto: Fix missing scrub of temp buffers with AES ctr and gcm algorithm

In function ctr_aes_crypt() there is a buffer used to process

remaining bytes < AES_BLOCK_SIZE. This buffer was not scrubbed and

thus could lead to expose of unwanted data. When the buffer is used

explicitly scrub it at the end of the code block to avoid exposure of

maybe sensitive data.

In a similar way the function gcm_aes_crypt() hat an error path where

the CPACF param block was not scrubbed. Instead of return early now

these error paths go to end of function where explicit scrubbing is

done. Similar with the buffers which are part of the gcm_sg_walk

structs from the variables gw_in and gw_out. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97592
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97592