Linux Kernel DCP Trusted Keys Stack Buffer Vulnerability

Vulnerability

A vulnerability in the Linux kernel's DCP trusted keys handling can lead to a crash during the encryption and decryption of blob encryption keys. This issue arises when vmalloc stack addresses are enabled, causing the DCP crypto driver to improperly manage stack buffers allocated with vmalloc. The vulnerability has been addressed by ensuring that the DCP crypto driver only receives buffers allocated with kmalloc.

Impact

The vulnerability can cause a kernel crash, disrupting system operations and potentially leading to a denial of service.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
9.0
impact
2.5
exploitability
4.0
remediation
0.0
relevance
0.0
threat
3.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.