A vulnerability labeled as very critical has been found in Linux Kernel up to 6.6.147/6.12.100/6.18.41/7.1.5/7.2-rc4. Impacted is the function find_or_insert_direct_key of the component fscrypt. Executing a manipulation can lead to use after free.

This vulnerability is tracked as CVE-2026-68148. The attack can be launched remotely. No exploit exists.

The affected component should be upgraded.