CVE-2026-98221
Published Oct 6, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix tpm2_load_cmd() boundary check tpm2_load_cmd() does boundary checks against the ASN.1 size i.e., payload->blob_len. Address this by passing the decoded blob size to tpm2_load_cmd(), and use it for the boundary checks.
Is your site exposed to CVE-2026-98221?
Run a free security scan — no signup, results in seconds.
EPSS — Exploit Prediction
0.0022
Probability of exploitation
0.11%
Percentile rank
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
References
Other References
https://git.kernel.org/stable/c/114f00d738f15dd8c7318369edcdc53dd6d08763
https://git.kernel.org/stable/c/134825dfc971fbf2b1d0f58f0b3bce8332ad0afb
https://git.kernel.org/stable/c/3fd487c69ad3161e358c33c170bab0cf02a071b7
https://git.kernel.org/stable/c/5afa57ea91481c6c49f194b0f5a5c4d96a4d7348
https://git.kernel.org/stable/c/9ddbc5f4bb498aff8096a5231574858a4bffee4f
https://git.kernel.org/stable/c/b020b447338872440142fe8a57350a483da86b7a
https://git.kernel.org/stable/c/cc86227fea28aed86c1fb52a884560b4440da198
Frequently Asked Questions
What is CVE-2026-98221? +
In the Linux kernel, the following vulnerability has been resolved:
KEYS: trusted: Fix tpm2_load_cmd() boundary check
tpm2_load_cmd() does boundary checks against the ASN.1 size i.e.,
payload->blob_len. Address this by passing the decoded blob size to
tpm2_load_cmd(), and use it for the boundary checks.
How do I check if I'm vulnerable to CVE-2026-98221? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.