8.4

CVE-2026-72151

tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt

In the Linux kernel, the following vulnerability has been resolved:

tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt

tpm_buf_append_salt() in drivers/char/tpm/tpm2-sessions.c calls
crypto_kpp_generate_public_key() and crypto_kpp_compute_shared_secret()
without installing a completion callback, discards both return values,
and immediately frees the kpp_request via kpp_request_free(). When the
resolved ecdh-nist-p256 KPP backend is asynchronous (atmel-ecc, HPRE,
keembay-ocs), either operation returns -EINPROGRESS and the deferred
completion worker dereferences the freed request.

The path fires automatically from the hwrng_fillfn kernel thread via
tpm_get_random -> tpm2_get_random -> tpm2_start_auth_session ->
tpm_buf_append_salt on every entropy poll, without any userland action.

Install crypto_req_done as the completion callback, wrap both KPP
operations in crypto_wait_req(), and propagate errors to the caller.
The wait is a no-op for synchronous backends.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 1085b8276bb4239daa7008f0dcd5c973e4bd690f
Version < 111e520efbe82b324bc42b1999b723c0619eea6d
Status affected
Version 1085b8276bb4239daa7008f0dcd5c973e4bd690f
Version < 934d1cd40e2893bf7a041b54f6afd1c008d7a21c
Status affected
Version 1085b8276bb4239daa7008f0dcd5c973e4bd690f
Version < 493333f167926c7adab8e7563e21ad71d8af84fa
Status affected
Version 1085b8276bb4239daa7008f0dcd5c973e4bd690f
Version < 73851a7c43dfa52d2ed9415889b33daf85da0ed9
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 6.10
Status affected
Version 0
Version < 6.10
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.40
Status unaffected
Version <= 7.1.*
Version 7.1.5
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.18% 0.081
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.4 2.5 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/111e520efbe82b324bc42b1999b723c0619eea6d
https://git.kernel.org/stable/c/934d1cd40e2893bf7a041b54f6afd1c008d7a21c
https://git.kernel.org/stable/c/493333f167926c7adab8e7563e21ad71d8af84fa
https://git.kernel.org/stable/c/73851a7c43dfa52d2ed9415889b33daf85da0ed9