{"id":"CVE-2026-98221","title":"In the Linux kernel, the following vulnerability has been resolved:\n\nKEYS: trusted: Fix tpm2_load_cmd() boundary check\n\ntpm2_load_cmd() does boundary checks against the ASN.1 size i.e.,\npayload->blob_len","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\nKEYS: trusted: Fix tpm2_load_cmd() boundary check\n\ntpm2_load_cmd() does boundary checks against the ASN.1 size i.e.,\npayload->blob_len. Address this by passing the deco…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= f2219745250f388edacabe6cca73654131c67d0a < cc86227fea28aed86c1fb52a884560b4440da198","Linux >= f2219745250f388edacabe6cca73654131c67d0a < b020b447338872440142fe8a57350a483da86b7a","Linux >= f2219745250f388edacabe6cca73654131c67d0a < 3fd487c69ad3161e358c33c170bab0cf02a071b7","Linux >= f2219745250f388edacabe6cca73654131c67d0a < 5afa57ea91481c6c49f194b0f5a5c4d96a4d7348","Linux >= f2219745250f388edacabe6cca73654131c67d0a < 9ddbc5f4bb498aff8096a5231574858a4bffee4f","Linux >= f2219745250f388edacabe6cca73654131c67d0a < 134825dfc971fbf2b1d0f58f0b3bce8332ad0afb","Linux >= f2219745250f388edacabe6cca73654131c67d0a < 114f00d738f15dd8c7318369edcdc53dd6d08763","Linux 5.13"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T09:18:09.003","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-98221","references":[{"url":"https://git.kernel.org/stable/c/114f00d738f15dd8c7318369edcdc53dd6d08763","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/134825dfc971fbf2b1d0f58f0b3bce8332ad0afb","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/3fd487c69ad3161e358c33c170bab0cf02a071b7","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/5afa57ea91481c6c49f194b0f5a5c4d96a4d7348","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9ddbc5f4bb498aff8096a5231574858a4bffee4f","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b020b447338872440142fe8a57350a483da86b7a","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/cc86227fea28aed86c1fb52a884560b4440da198","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-06T08:50:17.440Z","slug":"CVE-2026-98221","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\nKEYS: trusted: Fix tpm2_load_cmd() boundary check\n\ntpm2_load_cmd() does boundary checks against the ASN.1 size i.e.,\npayload->blob_len. Address this by passing the decoded blob size to\ntpm2_load_cmd(), and use it for the boundary checks.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}