<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cve-2026-46291 on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/cve-2026-46291/</link><description>Recent content in Cve-2026-46291 on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Tue, 18 Jun 2024 08:50:14 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/cve-2026-46291/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-46291: Linux CAAM HMAC Key Leak on Azure</title><link>https://zxcloudsecurity.co.uk/posts/cve-2026-46291-linux-caam-hmac-key-leak-azure/</link><pubDate>Thu, 18 Jun 2026 08:50:14 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2026-46291-linux-caam-hmac-key-leak-azure/</guid><description>CVE-2026-46291 exposes HMAC key material via unguarded hex dumps in the Linux kernel CAAM driver. Azure Linux VM users should patch promptly.</description><content:encoded><![CDATA[<p>🟡 <strong>Medium</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-46291">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-46291 is a vulnerability in the Linux kernel&rsquo;s CAAM (Cryptographic Acceleration and Assurance Module) driver, specifically affecting how HMAC key material is handled during hash digest key operations. The flaw can expose sensitive cryptographic key data through unguarded hex dumps, potentially leaking HMAC secrets into kernel logs or debug output. This matters because HMAC keys exposed in this way could undermine the integrity and authenticity guarantees of cryptographic operations running on affected systems, including those hosted in Azure environments using Linux-based virtual machines.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review your Azure Linux VM and AKS node configurations to ensure kernel debug logging and crash dump access is restricted to authorised personnel, and prioritise patching the Linux kernel to a version that includes this fix. Additionally, audit any workloads relying on kernel-level HMAC operations for secrets management to assess exposure risk.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-46291">CVE-2026-46291 crypto: caam - guard HMAC key hex dumps in hash_digest_key</a></p>
]]></content:encoded></item></channel></rss>