Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2026-80708

Published Aug 28, 2026

Overview

CVE-2026-80708 is a known-severity vulnerability. It was published on August 28, 2026.

Technical Description

In the Linux kernel, the following vulnerability has been resolved:

s390/zcrypt: Fix missing mem scrub at clear key import in cca_clr2cipherkey()

The helper function _ip_cprb_helper() uses internal buffer memory for

building and processing CPRBs. After use this buffer was never

scrubbed which could lead to leaving for example clear key material in

memory which could be exposed via tricky reuse of this same memory.

Extend the _ip_cprb_helper() function with another parameter 'scrub'

used to steer scrubbing of this buffer. So now the caller has the

opportunity to decide if scrubbing is needed or not.

Extend the clear key to secure key token import process in function

cca_clr2cipherkey() to tell the helper function from above to scrub

the cprb buffer when the clear key value is part of the request data.

Add explicit scrubbing on return from function cca_clr2cipherkey() for

the random EXOR buffer and the cprb buffer.

Overall this cleans the internal used buffer in case of clear key

i

Remediation

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Frequently Asked Questions

What is CVE-2026-80708?

CVE-2026-80708 is a known-severity vulnerability. It was published on August 28, 2026.

How severe is CVE-2026-80708?

CVSS score information is not yet available for this vulnerability. Check back as the CVE record is updated by NVD analysts.

How do I fix or remediate CVE-2026-80708?

Check the references section for vendor advisories, patches, and mitigation guidance. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2026-80708?

CyberStrike's AI-powered security agents can automatically detect CVE-2026-80708 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.