CVE-2026-93163 is a vulnerability in Linux Kernel
Published on September 17, 2026
hwrng: core - fix rng list on registration error
In the Linux kernel, the following vulnerability has been resolved:
hwrng: core - fix rng list on registration error
hwrng_register(rng) does the following:
1. Checks if rng has name and read methods set
2. Checks if the name already exists
3. Adds rng to global rng_list
4. May try to set rng to current_rng
If step 4 fails, it returns an error. However, it does not remove the
rng from rng_list, causing a dangling reference which can result in
use-after-free if the caller frees rng, since registration failed.
Add a list_del_init() cleanup step.
Products Associated with CVE-2026-93163
Want to know whenever a new CVE is published for Linux Kernel? stack.watch will email you.
Affected Versions
Linux:- Version 2bbb6983887fefc8026beab01198d30f47b7bd22 and below de4f1bcb61a73cc896decdbd27d61a34add93b53 is affected.
- Version 2bbb6983887fefc8026beab01198d30f47b7bd22 and below cf293c9c7424de0d04b51367d07f40570ce80231 is affected.
- Version 2bbb6983887fefc8026beab01198d30f47b7bd22 and below bee8d1fcdc8f389b595b0a4cf6fe8440f499458a is affected.
- Version 2bbb6983887fefc8026beab01198d30f47b7bd22 and below 3a5834db2b1ce25649f330e78efe1ccde78967fd is affected.
- Version 42802952a2725f85f7e36ee3b29593af5fe87197 is affected.
- Version 4.9.320 and below 4.10 is affected.
- Version 4.14 is affected.
- Before 4.14 is unaffected.
- Version 6.12.110, <= 6.12.* is unaffected.
- Version 6.18.52, <= 6.18.* is unaffected.
- Version 7.2.6, <= 7.2.* is unaffected.
- Version 7.3-rc1, <= * is unaffected.