CVE-2026-63823High· 7.8▾ TwilightIn the Linux kernel, the following vulnerability has been resolved: keys: Pin request_key_auth payload in instantiate paths A: request_key() B: KEYCTL_INSTANTIATE_IOV ================ ========================= create auth …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.1%
In the Linux kernel, the following vulnerability has been resolved:
keys: Pin request_key_auth payload in instantiate paths
A: request_key() B: KEYCTL_INSTANTIATE_IOV ================ =========================
create auth key store rka in auth key wait for helper get auth key load rka from auth key copy user payload sleep on #PF
helper completed detach and free rka destroy auth key wake up use rka->target_key USE-AFTER-FREE
Give request_key_auth payloads a refcount. Take a payload reference while authkey->sem stabilizes the payload and revocation state. Hold that reference across the instantiate and reject paths. Drop the auth key owning reference from revoke and destroy.
[jarkko: Replaced the first two paragraphs of text with an actual concurrency scenario.]
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.