In the Linux kernel, the following vulnerability has been resolved:
crypto: asymmetric_keys - prevent overflow in asymmetric_key_generate_id
Use check_add_overflow() to guard against potential integer overflows
when adding the binary blob lengths and the size of an asymmetric_key_id
structure and return ERR_PTR(-EOVERFLOW) accordingly. This prevents a
possible buffer overflow when copying data from potentially malicious
X.509 certificate fields that can be arbitrarily large, such as ASN.1
INTEGER serial numbers, issuer names, etc.
References
Configurations
No configuration.
History
30 Jul 2026, 06:24
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
14 Jul 2026, 13:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
19 Jan 2026, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
11 Jan 2026, 17:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
24 Dec 2025, 11:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-24 11:16
Updated : 2026-07-30 06:24
NVD link : CVE-2025-68724
Mitre link : CVE-2025-68724
CVE.ORG link : CVE-2025-68724
JSON object : View
Products Affected
No product.
CWE
No CWE.
