In the Linux kernel, the following vulnerability has been resolved:
KEYS: trusted: dcp: fix improper sg use with CONFIG_VMAP_STACK=y
With vmalloc stack addresses enabled (CONFIG_VMAP_STACK=y) DCP trusted keys can crash during en- and decryption of the blob encryption key via the DCP crypto driver. This is caused by improperly using sg_init_one() with vmalloc'd stack buffers (plain_key_blob).
Fix this by always using kmalloc() for buffers we give to the DCP crypto driver.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade linux | Jul 27, 2026 | Jul 27, 2026 |
| Ubuntu | — | Upgrade linux-image-lowlatency-64k-hwe-24.04Upgrade linux-image-lowlatency-hwe-24.04Upgrade linux-image-6.11.0-1016-oracleUpgrade linux-image-gcpUpgrade linux-image-6.11.0-1015-azureUpgrade linux-image-6.11.0-1013-raspiUpgrade linux-image-6.11.0-1015-gcp-64kUpgrade linux-image-6.11.0-1014-awsUpgrade linux-image-6.11.0-1015-azure-fdeUpgrade linux-image-6.11.0-1022-oemUpgrade linux-image-lowlatencyUpgrade linux-image-azureUpgrade linux-image-azure-fdeUpgrade linux-image-6.11.0-1010-realtimeUpgrade linux-image-6.11.0-26-generic-64kUpgrade linux-image-genericUpgrade linux-image-oem-24.04bUpgrade linux-image-raspiUpgrade linux-image-lowlatency-64kUpgrade linux-image-generic-64kUpgrade linux-image-6.11.0-1014-lowlatencyUpgrade linux-image-6.11.0-1014-lowlatency-64kUpgrade linux-image-6.11.0-26-genericUpgrade linux-image-oracleUpgrade linux-image-oracle-64kUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-awsUpgrade linux-image-6.11.0-1015-gcpUpgrade linux-image-realtimeUpgrade linux-image-gcp-64kUpgrade linux-image-virtual-hwe-24.04Upgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-virtualUpgrade linux-image-6.11.0-1016-oracle-64k | May 21, 2025 | Feb 27, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub