CVE-2026-52978

Description

A flaw was found in the Linux kernel's Platform Security Processor (PSP) networking component. A local user without administrative privileges could exploit this vulnerability by utilizing the dev-set and key-rotate netlink operations. These operations, which modify sensitive PSP version configuration and cryptographic key material, did not properly enforce administrator permissions. This could lead to unauthorized modification of critical system security settings and cryptographic keys.

Understanding the Weakness (CWE)

Access Control

Technical Impact: Gain Privileges or Assume Identity

A user can access restricted functionality and/or sensitive information that may include administrative functionality and user accounts.

Frequently Asked Questions

Want to get errata notifications? Sign up here.