Review reviewHigh

CVE-2026-63823

Linux

In the Linux kernel, the following vulnerability has been resolved: keys: Pin request_key_auth payload in instantiate paths A: request_key() B: KEYCTL_INSTANTIATE_IOV ================ ========================= create auth key store rka in auth key wait for helper get auth key load rka from auth key copy user payload sleep on #PF helper completed detach and free rka destroy auth key wake up use rka->target_key **USE-AFTER-FREE** Give request_key_auth payloads a refcount. Take a payload reference while authkey->sem stabilizes the payload and revocation state. Hold that reference across the in...

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.19
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: keys: Pin request_key_auth payload in instantiate paths A: request_key() B: KEYCTL_INSTANTIATE_IOV ================ ========================= create auth key store rka in auth key wait for helper get auth key load rka from auth key copy user payload sleep on #PF helper completed detach and free rka destroy auth key wake up use rka->target_key **USE-AFTER-FREE** Give request_key_auth payloads a refcount. Take a payload reference while authkey->sem stabilizes the payload and revocation state. Hold that reference across the in...

Affected product and versions

Product
Linux
Affected versions
>= b5f545c880a2a47947ba2118b2509644ab7a2969 < d8274181b0f28d450b42489723a5ba81042158d7, >= b5f545c880a2a47947ba2118b2509644ab7a2969 < 4982bfabce6b33b3c9eddb4fb900fe5568b7cf91, >= b5f545c880a2a47947ba2118b2509644ab7a2969 < 708709c65a1832a99b0eef8ae46e343ddaca3d06, >= b5f545c880a2a47947ba2118b2509644ab7a2969 < 35ab4db86774d82389e4b9559e26ab7f68d8e395, >= b5f545c880a2a47947ba2118b2509644ab7a2969 < f9b68632ac93cc742f2e411021c4dbfe452ea0c2, >= b5f545c880a2a47947ba2118b2509644ab7a2969 < 7216ce8cb12fee44e309503955bb83806b106129, >= b5f545c880a2a47947ba2118b2509644ab7a2969 < 83c0a1cb296d955d5f4d1f0bd8a769ba8ed8c29f, >= b5f545c880a2a47947ba2118b2509644ab7a2969 < fd15b457a86939c38aa12116adabd8ff686c5e51, >= 2.6.16
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available