-
CVE-2026-80833
- EPSS 0.16%
- Veröffentlicht 04.09.2026 15:54:41
- Zuletzt bearbeitet 03.10.2026 11:17:39
- Erkennungen
crypto: sun8i-ss - Remove crypto_rng interface
In the Linux kernel, the following vulnerability has been resolved: crypto: sun8i-ss - Remove crypto_rng interface Since the crypto_rng interface for hardware PRNGs is unused and is redundant with hwrng and the actual Linux RNG, it's being phased out. Most drivers for it were already removed. Go ahead and remove the sun8i-ss support which is one of the only remaining ones. As usual for crypto_rng, this driver was also buggy: its ->generate() function had a use-after-free vulnerability due to using wait_for_completion_interruptible_timeout() without handling shutting down the DMA operation if a signal is sent. Also, it had a buffer overread bug in the line 'memcpy(ctx->seed, d + dlen, ctx->slen);'. There's no point in fixing these bugs separately only to remove the code anyway, so this commit is marked with Fixes and Cc stable.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt
Linux
Default Statusunaffected
Version
ac2614d721dea2ff273af19c6c5d508d58a2bb3e
Version <
9127d2a88c1795ddc4ba7687fea01cab1908fae1
Status
affected
Version
ac2614d721dea2ff273af19c6c5d508d58a2bb3e
Version <
64f3406ad082c00fb7a80240a24943ccb6d9a538
Status
affected
Version
ac2614d721dea2ff273af19c6c5d508d58a2bb3e
Version <
6117968fe2cdcde28ac3aa6ec814485320af4049
Status
affected
Version
ac2614d721dea2ff273af19c6c5d508d58a2bb3e
Version <
a41e4ba94ad4571aa2e566baa395e6e871e0fd4f
Status
affected
Version
ac2614d721dea2ff273af19c6c5d508d58a2bb3e
Version <
d29ccf9eeb67d775221e49a079caa1af83427afa
Status
affected
Version
ac2614d721dea2ff273af19c6c5d508d58a2bb3e
Version <
7c257a295e05ceb8f78aa3efecc4e9ce19c3313f
Status
affected
Version
ac2614d721dea2ff273af19c6c5d508d58a2bb3e
Version <
8ab58786b4c63b8f1b6c522f33bb67a3c8c2791f
Status
affected
Version
ac2614d721dea2ff273af19c6c5d508d58a2bb3e
Version <
a78446ee6fae86ac8733f120e3ffce2e5d9384f5
Status
affected
HerstellerLinux
≫
Produkt
Linux
Default Statusaffected
Version
5.10
Status
affected
Version
0
Version <
5.10
Status
unaffected
Version <=
5.10.*
Version
5.10.271
Status
unaffected
Version <=
5.15.*
Version
5.15.222
Status
unaffected
Version <=
6.1.*
Version
6.1.189
Status
unaffected
Version <=
6.6.*
Version
6.6.158
Status
unaffected
Version <=
6.12.*
Version
6.12.109
Status
unaffected
Version <=
6.18.*
Version
6.18.50
Status
unaffected
Version <=
7.2.*
Version
7.2.3
Status
unaffected
Version <=
*
Version
7.3-rc1
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.05 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://git.kernel.org/stable/c/8ab58786b4c63b8f1b6c522f33bb67a3c8c2791f
https://git.kernel.org/stable/c/a78446ee6fae86ac8733f120e3ffce2e5d9384f5
https://git.kernel.org/stable/c/7c257a295e05ceb8f78aa3efecc4e9ce19c3313f
https://git.kernel.org/stable/c/d29ccf9eeb67d775221e49a079caa1af83427afa
https://git.kernel.org/stable/c/6117968fe2cdcde28ac3aa6ec814485320af4049
https://git.kernel.org/stable/c/64f3406ad082c00fb7a80240a24943ccb6d9a538
https://git.kernel.org/stable/c/9127d2a88c1795ddc4ba7687fea01cab1908fae1
https://git.kernel.org/stable/c/a41e4ba94ad4571aa2e566baa395e6e871e0fd4f