---
id: CVE-2026-98222
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  KEYS: encrypted: fix integer overflow of datablob_len

  encrypted_key_alloc() stores datablob_len in a u16
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  KEYS: encrypted: fix integer overflow of datablob_len

  encrypted_key_alloc() stores datablob_len in a u16. It is computed from
  multiple string and payload lengths. If t…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 7e70cb4978507cf31d76b90e4cfb4c28cad87f0c <
    1e720f63dbafc093a8f5d519f05b67724993edd4
  - >-
    Linux >= 7e70cb4978507cf31d76b90e4cfb4c28cad87f0c <
    a1a98eca102b1cbbc37ff9eaa197ae4e6a3ea4b0
  - >-
    Linux >= 7e70cb4978507cf31d76b90e4cfb4c28cad87f0c <
    cca38f2102a4cd35eda8d48950df4817b4b24757
  - >-
    Linux >= 7e70cb4978507cf31d76b90e4cfb4c28cad87f0c <
    8697c431e297eb0d0ab13dda6bc172b48a34f05c
  - Linux 2.6.38
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:09.153'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98222'
references:
  - url: 'https://git.kernel.org/stable/c/1e720f63dbafc093a8f5d519f05b67724993edd4'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/8697c431e297eb0d0ab13dda6bc172b48a34f05c'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/a1a98eca102b1cbbc37ff9eaa197ae4e6a3ea4b0'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/cca38f2102a4cd35eda8d48950df4817b4b24757'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.440Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

KEYS: encrypted: fix integer overflow of datablob_len

encrypted_key_alloc() stores datablob_len in a u16. It is computed from
multiple string and payload lengths. If the result exceeds U16_MAX, the
assignment truncates the allocation size. KASAN reports a 32760-byte
slab-out-of-bounds write when __ekey_init() copies the master key
description into the undersized buffer.

The total payload length stored in key->datalen is also a u16. Use
check_add_overflow() to reject values that do not fit either destination,
and use kzalloc_flex() for the flexible-array allocation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
