-

CVE-2026-80833

Medienbericht

crypto: sun8i-ss - Remove crypto_rng interface

In the Linux kernel, the following vulnerability has been resolved:

crypto: sun8i-ss - Remove crypto_rng interface

Since the crypto_rng interface for hardware PRNGs is unused and is
redundant with hwrng and the actual Linux RNG, it's being phased out.
Most drivers for it were already removed.  Go ahead and remove the
sun8i-ss support which is one of the only remaining ones.

As usual for crypto_rng, this driver was also buggy: its ->generate()
function had a use-after-free vulnerability due to using
wait_for_completion_interruptible_timeout() without handling shutting
down the DMA operation if a signal is sent.  Also, it had a buffer
overread bug in the line 'memcpy(ctx->seed, d + dlen, ctx->slen);'.
There's no point in fixing these bugs separately only to remove the code
anyway, so this commit is marked with Fixes and Cc stable.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version ac2614d721dea2ff273af19c6c5d508d58a2bb3e
Version < 9127d2a88c1795ddc4ba7687fea01cab1908fae1
Status affected
Version ac2614d721dea2ff273af19c6c5d508d58a2bb3e
Version < 64f3406ad082c00fb7a80240a24943ccb6d9a538
Status affected
Version ac2614d721dea2ff273af19c6c5d508d58a2bb3e
Version < 6117968fe2cdcde28ac3aa6ec814485320af4049
Status affected
Version ac2614d721dea2ff273af19c6c5d508d58a2bb3e
Version < a41e4ba94ad4571aa2e566baa395e6e871e0fd4f
Status affected
Version ac2614d721dea2ff273af19c6c5d508d58a2bb3e
Version < d29ccf9eeb67d775221e49a079caa1af83427afa
Status affected
Version ac2614d721dea2ff273af19c6c5d508d58a2bb3e
Version < 7c257a295e05ceb8f78aa3efecc4e9ce19c3313f
Status affected
Version ac2614d721dea2ff273af19c6c5d508d58a2bb3e
Version < 8ab58786b4c63b8f1b6c522f33bb67a3c8c2791f
Status affected
Version ac2614d721dea2ff273af19c6c5d508d58a2bb3e
Version < a78446ee6fae86ac8733f120e3ffce2e5d9384f5
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.10
Status affected
Version 0
Version < 5.10
Status unaffected
Version <= 5.10.*
Version 5.10.271
Status unaffected
Version <= 5.15.*
Version 5.15.222
Status unaffected
Version <= 6.1.*
Version 6.1.189
Status unaffected
Version <= 6.6.*
Version 6.6.158
Status unaffected
Version <= 6.12.*
Version 6.12.109
Status unaffected
Version <= 6.18.*
Version 6.18.50
Status unaffected
Version <= 7.2.*
Version 7.2.3
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.16% 0.05
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
08.09.2026 20:38
https://git.kernel.org/stable/c/8ab58786b4c63b8f1b6c522f33bb67a3c8c2791f
https://git.kernel.org/stable/c/a78446ee6fae86ac8733f120e3ffce2e5d9384f5
https://git.kernel.org/stable/c/7c257a295e05ceb8f78aa3efecc4e9ce19c3313f
https://git.kernel.org/stable/c/d29ccf9eeb67d775221e49a079caa1af83427afa
https://git.kernel.org/stable/c/6117968fe2cdcde28ac3aa6ec814485320af4049
https://git.kernel.org/stable/c/64f3406ad082c00fb7a80240a24943ccb6d9a538
https://git.kernel.org/stable/c/9127d2a88c1795ddc4ba7687fea01cab1908fae1
https://git.kernel.org/stable/c/a41e4ba94ad4571aa2e566baa395e6e871e0fd4f