CVE-2026-80709
Last modified
CVE-2026-80709 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs There is a wrong upper limit check for the domain value when an EP11 CPRB is processed for sending to a crypto card. This check is only active on custom device nodes but may lead to access heap memory behind perms->adm when an administrative CPRB is sent. Add correct limit (AP_DOMAINS = 256) checking to fix this.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix wrong domain value verification with EP11 CPRBs There is a wrong upper limit check for the domain value when an EP11 CPRB is processed for sending to a crypto card. This check is only active on custom device nodes but may lead to access heap memory behind perms->adm when an administrative CPRB is sent. Add correct limit (AP_DOMAINS = 256) checking to fix this.
Metrics
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux | >= cfd68b33094e1a92249850ff3c3c92ae9112a541, < 4589f742718d0256ea6dd1f5a78be6e689bdb8aa; >= cfd68b33094e1a92249850ff3c3c92ae9112a541, < b505dcc8307d64468b463dfad45a03bf865c637e; >= cfd68b33094e1a92249850ff3c3c92ae9112a541, < 13e53d6ae1c3b2ff1be75b9ef09be26f4ec3ce15; >= cfd68b33094e1a92249850ff3c3c92ae9112a541, < 672b12940e3f1336dfed5287412a71500adf2a76; >= cfd68b33094e1a92249850ff3c3c92ae9112a541, < 1223477ca88e2396eca440919d0ca8754df79bd5; >= cfd68b33094e1a92249850ff3c3c92ae9112a541, < 983279d7f86ade73db86f886e09172dd567031b5 |
| Linux | Linux | 5.18 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-80709?
How severe is CVE-2026-80709?
How do I fix CVE-2026-80709?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-80703In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80704In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80705In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80706In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-80707In the Linux kernel, the following vulnerability has been re…7.5
- CVE-2026-80708In the Linux kernel, the following vulnerability has been re…
- CVE-2026-8071The Anti-Spam by CleanTalk. Spam protection WordPress plugin…8.8
- CVE-2026-80710In the Linux kernel, the following vulnerability has been re…7.8
- CVE-2026-80711In the Linux kernel, the following vulnerability has been re…
- CVE-2026-80712In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-80713In the Linux kernel, the following vulnerability has been re…8.4
- CVE-2026-80714In the Linux kernel, the following vulnerability has been re…9.8
Are you affected by CVE-2026-80709?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
