CVE-2026-80924: Linux

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In the Linux kernel, the following vulnerability has been resolved: crypto: krb5 - use kfree_sensitive() for derived key buffers crypto_krb5_prepare_encryption() and crypto_krb5_prepare_checksum() free the buffer holding the freshly derived keys with plain kfree(), leaving the key material behind in the freed slab object.

Affected products

  • Linux Linux: from 6.15, before 6.18.49 (fixed in 6.18.49); from 6.19, before 7.1.13 (fixed in 7.1.13); from 7.2, before 7.2.3 (fixed in 7.2.3)

Published 2026-09-09. Last modified 2026-09-10.