← Retour à la recherche de CVE

CVE-2026-72103

Linux kernel

Description

In the Linux kernel, the following vulnerability has been resolved: dm: avoid leaking the caller-s thread keyring via the table device file The refactoring in commit a28d893eb327 (-md: port block device access to file-) accidentally causes the caller-s thread keyring to be kept alive long beyond the caller-s lifetime. As a result, -cryptsetup luksSuspend- silently fails to wipe the LUKS volume key from memory. In detail: -cryptsetup luksOpen- uses its supposedly ephemeral thread keyring to pass the volume key to the kernel. dm-crypt-s crypt_set_keyring_key() copies the key material into its own crypt_config structure and then drops its own reference to the key in the keyring with key_put(). With this fix, restoring pre-v6.9 behavior, the copy in the thread keyring is then promptly garbage collected, such that exactly one copy of the volume key remains. This single copy is correctly wiped from memory on -cryptsetup luksSuspend-. Without this fix, the thread keyring and the volume key in it remains. This second copy is only freed on -luksClose-. -luksSuspend- neither knows about this copy nor has any way to remove it, so the key remains recoverable from RAM after a suspend that is documented to have wiped it. This fix should not introduce new security problems, as the code is anyway gated by CAP_SYS_ADMIN. The device-mapper core, not the calling task, is the legitimate owner of this long-lived file.

CVSS 7.3EPSS 0.159%Risque 0.74
Voir la source
Publication
2026-08-15 06:21:24
Versions concernées
unknown
Type
Noyau
Dernière modification
2026-08-17 06:18:09
Vecteur
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L