CVE-2026-93159
In the Linux kernel, the following vulnerability has been resolved:
crypto: atmel-sha204a - fix heap info leak on I2C transfer failure
The nonblocking RNG path allocates a work_data structure to track the state of an in-flight asynchronous I2C request. This pointer is stored in rng->priv and later consumed by the read path once the transaction completes.
If the underlying I2C transfer fails, the completion callback is invoked with a non-zero status. In this case, the allocated work_data is not usable for producing RNG output and must not remain associated with the hwrng state.
Previously, the failure path only logged a warning but left the pointer state uncleared, which can result in subsequent read attempts observing stale state and interpreting it as valid completion data.
Leer descripción completaMostrar menos
Fix this by freeing the pending work_data. The I2C transaction reports an error. This ensures that failed requests do not leave residual state behind that could be interpreted as valid RNG data on later reads. Clearing rng->priv is done at the subsequent call to nonblocking read.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.22%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/0d6db386133d9230befb77967bbf130443964860
- https://git.kernel.org/stable/c/28cc179252347718f97045dd5ea74165609dbd7d
- https://git.kernel.org/stable/c/4e76d85e505b7451925efbcd67c015e8c2440c68
- https://git.kernel.org/stable/c/72bbf11ba14bd7d5fbf31a1ec42fff608b657f74
- https://git.kernel.org/stable/c/94abda77b57a35b82bba0365bad072d94d67ffe9
- https://git.kernel.org/stable/c/a430b5b6d2ddd2b266330f8507a655be1148347d
- https://git.kernel.org/stable/c/bcac9052e19490231ff6e0678a06bd2fcf8db3af
- https://git.kernel.org/stable/c/f4d347fb1309b69ea6f817a17e6b2893c8d754b7
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-93159",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "da001fb651b00e1deeaf24767dd691ae8152a4f5",
"lessThan": "a430b5b6d2ddd2b266330f8507a655be1148347d",
"versionType": "git"
},
{
"status": "affected",
"version": "da001fb651b00e1deeaf24767dd691ae8152a4f5",
"lessThan": "4e76d85e505b7451925efbcd67c015e8c2440c68",
"versionType": "git"
},
{
"status": "affected",
"version": "da001fb651b00e1deeaf24767dd691ae8152a4f5",
"lessThan": "bcac9052e19490231ff6e0678a06bd2fcf8db3af",
"versionType": "git"
},
{
"status": "affected",
"version": "da001fb651b00e1deeaf24767dd691ae8152a4f5",
"lessThan": "28cc179252347718f97045dd5ea74165609dbd7d",
"versionType": "git"
},
{
"status": "affected",
"version": "da001fb651b00e1deeaf24767dd691ae8152a4f5",
"lessThan": "0d6db386133d9230befb77967bbf130443964860",
"versionType": "git"
},
{
"status": "affected",
"version": "da001fb651b00e1deeaf24767dd691ae8152a4f5",
"lessThan": "f4d347fb1309b69ea6f817a17e6b2893c8d754b7",
"versionType": "git"
},
{
"status": "affected",
"version": "da001fb651b00e1deeaf24767dd691ae8152a4f5",
"lessThan": "94abda77b57a35b82bba0365bad072d94d67ffe9",
"versionType": "git"
},
{
"status": "affected",
"version": "da001fb651b00e1deeaf24767dd691ae8152a4f5",
"lessThan": "72bbf11ba14bd7d5fbf31a1ec42fff608b657f74",
"versionType": "git"
}
],
"programFiles": [
"drivers/crypto/atmel-sha204a.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.3"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.3",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.270",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.221",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.188",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.157",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.110",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.52",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.2.6",
"versionType": "semver",
"lessThanOrEqual": "7.2.*"
},
{
"status": "unaffected",
"version": "7.3-rc1",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/crypto/atmel-sha204a.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-09-17T17:18:11.277",
"references": [
{
"url": "https://git.kernel.org/stable/c/0d6db386133d9230befb77967bbf130443964860",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/28cc179252347718f97045dd5ea74165609dbd7d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/4e76d85e505b7451925efbcd67c015e8c2440c68",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/72bbf11ba14bd7d5fbf31a1ec42fff608b657f74",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/94abda77b57a35b82bba0365bad072d94d67ffe9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a430b5b6d2ddd2b266330f8507a655be1148347d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/bcac9052e19490231ff6e0678a06bd2fcf8db3af",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/f4d347fb1309b69ea6f817a17e6b2893c8d754b7",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: atmel-sha204a - fix heap info leak on I2C transfer failure\n\nThe nonblocking RNG path allocates a work_data structure to track the\nstate of an in-flight asynchronous I2C request. This pointer is stored\nin rng->priv and later consumed by the read path once the transaction\ncompletes.\n\nIf the underlying I2C transfer fails, the completion callback is invoked\nwith a non-zero status. In this case, the allocated work_data is not\nusable for producing RNG output and must not remain associated with the\nhwrng state.\n\nPreviously, the failure path only logged a warning but left the pointer\nstate uncleared, which can result in subsequent read attempts observing\nstale state and interpreting it as valid completion data.\n\nFix this by freeing the pending work_data. The I2C transaction reports\nan error. This ensures that failed requests do not leave residual state\nbehind that could be interpreted as valid RNG data on later reads.\nClearing rng->priv is done at the subsequent call to nonblocking read."
}
],
"lastModified": "2026-09-17T17:18:11.277",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}