{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-74566",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2026-08-15T05:44:03.917Z",
        "datePublished": "2026-08-15T12:28:07.628Z",
        "dateUpdated": "2026-08-19T16:39:06.890Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-08-19T16:39:06.890Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nkeys: make keyring key-chunk byte order agree with keyring_diff_objects()\n\nkeyring_get_key_chunk() loads description bytes into the index chunk low\naddress first, while keyring_diff_objects() numbers the first differing\nbit from the low end and folds the absolute byte index into the level\nwithout removing the inline-prefix offset the level already carries.\nThe two disagree on byte order and bit position, so the array can be\ntold two keys first differ at a bit that does not differ in the chunk\nthe walker uses, letting crafted descriptions collide into one node.\n\nLoad the chunk in the order keyring_diff_objects() assumes and drop the\ninline-prefix length when folding the byte index into the level.  This\nonly changes the in-memory ordering used to place keys within a keyring;\nadd, search and read of non-colliding keys are unaffected."
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "security/keys/keyring.c"
                    ],
                    "versions": [
                        {
                            "version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
                            "lessThan": "414bcf37d81ce9b3823aabc06b04c97fdcbe489b",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
                            "lessThan": "abe43c661efb753d5ee35ad8ace4bbb16fa9afd0",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
                            "lessThan": "f81920917074e3c4ad4fba06fe8c56738d010606",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
                            "lessThan": "bd0f976ef89dce6db458bf75bc2cf51127becc41",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
                            "lessThan": "7269df3e7fcfa308e6a456305162f7788747bdbd",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
                            "lessThan": "3d9f16c0b643ceac305526b2e2fe25c2c6166926",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
                            "lessThan": "7e5397a3fed0dee7779bd084bec3c0584db3c930",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "f771fde82051976a6fc0fd570f8b86de4a92124b",
                            "lessThan": "58565eef0f8d861aae92abfb7658458d661cee17",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "security/keys/keyring.c"
                    ],
                    "versions": [
                        {
                            "version": "5.3",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "5.3",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.265",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.216",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.183",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.151",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.103",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.18.44",
                            "lessThanOrEqual": "6.18.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.1.8",
                            "lessThanOrEqual": "7.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.2",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.3",
                                    "versionEndExcluding": "5.10.265"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.3",
                                    "versionEndExcluding": "5.15.216"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.3",
                                    "versionEndExcluding": "6.1.183"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.3",
                                    "versionEndExcluding": "6.6.151"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.3",
                                    "versionEndExcluding": "6.12.103"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.3",
                                    "versionEndExcluding": "6.18.44"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.3",
                                    "versionEndExcluding": "7.1.8"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "5.3",
                                    "versionEndExcluding": "7.2"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/414bcf37d81ce9b3823aabc06b04c97fdcbe489b"
                },
                {
                    "url": "https://git.kernel.org/stable/c/abe43c661efb753d5ee35ad8ace4bbb16fa9afd0"
                },
                {
                    "url": "https://git.kernel.org/stable/c/f81920917074e3c4ad4fba06fe8c56738d010606"
                },
                {
                    "url": "https://git.kernel.org/stable/c/bd0f976ef89dce6db458bf75bc2cf51127becc41"
                },
                {
                    "url": "https://git.kernel.org/stable/c/7269df3e7fcfa308e6a456305162f7788747bdbd"
                },
                {
                    "url": "https://git.kernel.org/stable/c/3d9f16c0b643ceac305526b2e2fe25c2c6166926"
                },
                {
                    "url": "https://git.kernel.org/stable/c/7e5397a3fed0dee7779bd084bec3c0584db3c930"
                },
                {
                    "url": "https://git.kernel.org/stable/c/58565eef0f8d861aae92abfb7658458d661cee17"
                }
            ],
            "title": "keys: make keyring key-chunk byte order agree with keyring_diff_objects()",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}