Linux 6.9 change prevents LUKS suspend from clearing encryption keys in RAM

A recent change in the Linux kernel, introduced in version 6.9, alters LUKS suspend behavior. The modification stops the routine that previously wiped disk‑encryption keys

A recent change in the Linux kernel, introduced in version 6.9, alters LUKS suspend behavior. The modification stops the routine that previously wiped disk‑encryption keys from RAM. As a result, keys remain in memory after a system suspend operation. The change was documented by a user on the Mathstodon network. Security analysts note that retaining keys could increase exposure if the machine is compromised. The Linux community is reviewing the impact of the adjustment. Distributions may need to issue patches or guidance for affected users. Users concerned about key leakage are advised to monitor kernel updates and consider alternative suspend methods.