CVE-2026-93159 is a vulnerability in Linux Kernel
Published on September 17, 2026
crypto: atmel-sha204a - fix heap info leak on I2C transfer failure
In the Linux kernel, the following vulnerability has been resolved:
crypto: atmel-sha204a - fix heap info leak on I2C transfer failure
The nonblocking RNG path allocates a work_data structure to track the
state of an in-flight asynchronous I2C request. This pointer is stored
in rng->priv and later consumed by the read path once the transaction
completes.
If the underlying I2C transfer fails, the completion callback is invoked
with a non-zero status. In this case, the allocated work_data is not
usable for producing RNG output and must not remain associated with the
hwrng state.
Previously, the failure path only logged a warning but left the pointer
state uncleared, which can result in subsequent read attempts observing
stale state and interpreting it as valid completion data.
Fix this by freeing the pending work_data. The I2C transaction reports
an error. This ensures that failed requests do not leave residual state
behind that could be interpreted as valid RNG data on later reads.
Clearing rng->priv is done at the subsequent call to nonblocking read.
Products Associated with CVE-2026-93159
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version da001fb651b00e1deeaf24767dd691ae8152a4f5 and below a430b5b6d2ddd2b266330f8507a655be1148347d is affected.
- Version da001fb651b00e1deeaf24767dd691ae8152a4f5 and below 4e76d85e505b7451925efbcd67c015e8c2440c68 is affected.
- Version da001fb651b00e1deeaf24767dd691ae8152a4f5 and below bcac9052e19490231ff6e0678a06bd2fcf8db3af is affected.
- Version da001fb651b00e1deeaf24767dd691ae8152a4f5 and below 28cc179252347718f97045dd5ea74165609dbd7d is affected.
- Version da001fb651b00e1deeaf24767dd691ae8152a4f5 and below 0d6db386133d9230befb77967bbf130443964860 is affected.
- Version da001fb651b00e1deeaf24767dd691ae8152a4f5 and below f4d347fb1309b69ea6f817a17e6b2893c8d754b7 is affected.
- Version da001fb651b00e1deeaf24767dd691ae8152a4f5 and below 94abda77b57a35b82bba0365bad072d94d67ffe9 is affected.
- Version da001fb651b00e1deeaf24767dd691ae8152a4f5 and below 72bbf11ba14bd7d5fbf31a1ec42fff608b657f74 is affected.
- Version 5.3 is affected.
- Before 5.3 is unaffected.
- Version 5.10.270, <= 5.10.* is unaffected.
- Version 5.15.221, <= 5.15.* is unaffected.
- Version 6.1.188, <= 6.1.* is unaffected.
- Version 6.6.157, <= 6.6.* is unaffected.
- Version 6.12.110, <= 6.12.* is unaffected.
- Version 6.18.52, <= 6.18.* is unaffected.
- Version 7.2.6, <= 7.2.* is unaffected.
- Version 7.3-rc1, <= * is unaffected.