CVE-2026-52978
Description
A flaw was found in the Linux kernel's Platform Security Processor (PSP) networking component. A local user without administrative privileges could exploit this vulnerability by utilizing the dev-set and key-rotate netlink operations. These operations, which modify sensitive PSP version configuration and cryptographic key material, did not properly enforce administrator permissions. This could lead to unauthorized modification of critical system security settings and cryptographic keys.
Understanding the Weakness (CWE)
Access Control
Technical Impact: Gain Privileges or Assume Identity
A user can access restricted functionality and/or sensitive information that may include administrative functionality and user accounts.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.