← All Advisories

CVE-2026-97590

Last refreshed2026-10-03

Status: UPDATED  |  Advisory ID: CVE-2026-97590

Key Details

CVECVE-2026-97590
Affected productsLinux Linux

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
LinuxLinux
SubsystemsGeneral OT
SectorsMultiple

What to Know

In the Linux kernel, the following vulnerability has been resolved:

s390/crypto: Fix missing scrub of temp buffers with PAES algorithm

In function ctr_paes_do_crypt() there is a buffer used to process

remaining bytes < AES_BLOCK_SIZE. This buffer was not scrubbed and

thus could lead to expose of unwanted data. Rework the code to

explicitly scrub the buffer at the end of the function to avoid

exposure of maybe sensitive data.

In function __xts_2keys_prep_param() change the existing scrub to

clean the whole param block instead of just the key field. (NVD)

What to Do

Monitor Linux's web page for any future patch releases.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-97590
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-97590