---
id: CVE-2026-98221
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  KEYS: trusted: Fix tpm2_load_cmd() boundary check

  tpm2_load_cmd() does boundary checks against the ASN.1 size i.e.,
  payload->blob_len
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  KEYS: trusted: Fix tpm2_load_cmd() boundary check

  tpm2_load_cmd() does boundary checks against the ASN.1 size i.e.,
  payload->blob_len. Address this by passing the deco…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= f2219745250f388edacabe6cca73654131c67d0a <
    cc86227fea28aed86c1fb52a884560b4440da198
  - >-
    Linux >= f2219745250f388edacabe6cca73654131c67d0a <
    b020b447338872440142fe8a57350a483da86b7a
  - >-
    Linux >= f2219745250f388edacabe6cca73654131c67d0a <
    3fd487c69ad3161e358c33c170bab0cf02a071b7
  - >-
    Linux >= f2219745250f388edacabe6cca73654131c67d0a <
    5afa57ea91481c6c49f194b0f5a5c4d96a4d7348
  - >-
    Linux >= f2219745250f388edacabe6cca73654131c67d0a <
    9ddbc5f4bb498aff8096a5231574858a4bffee4f
  - >-
    Linux >= f2219745250f388edacabe6cca73654131c67d0a <
    134825dfc971fbf2b1d0f58f0b3bce8332ad0afb
  - >-
    Linux >= f2219745250f388edacabe6cca73654131c67d0a <
    114f00d738f15dd8c7318369edcdc53dd6d08763
  - Linux 5.13
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:09.003'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98221'
references:
  - url: 'https://git.kernel.org/stable/c/114f00d738f15dd8c7318369edcdc53dd6d08763'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/134825dfc971fbf2b1d0f58f0b3bce8332ad0afb'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3fd487c69ad3161e358c33c170bab0cf02a071b7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/5afa57ea91481c6c49f194b0f5a5c4d96a4d7348'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9ddbc5f4bb498aff8096a5231574858a4bffee4f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b020b447338872440142fe8a57350a483da86b7a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/cc86227fea28aed86c1fb52a884560b4440da198'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.440Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

KEYS: trusted: Fix tpm2_load_cmd() boundary check

tpm2_load_cmd() does boundary checks against the ASN.1 size i.e.,
payload->blob_len. Address this by passing the decoded blob size to
tpm2_load_cmd(), and use it for the boundary checks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
