-

CVE-2026-93159

crypto: atmel-sha204a - fix heap info leak on I2C transfer failure

In the Linux kernel, the following vulnerability has been resolved:

crypto: atmel-sha204a - fix heap info leak on I2C transfer failure

The nonblocking RNG path allocates a work_data structure to track the
state of an in-flight asynchronous I2C request. This pointer is stored
in rng->priv and later consumed by the read path once the transaction
completes.

If the underlying I2C transfer fails, the completion callback is invoked
with a non-zero status. In this case, the allocated work_data is not
usable for producing RNG output and must not remain associated with the
hwrng state.

Previously, the failure path only logged a warning but left the pointer
state uncleared, which can result in subsequent read attempts observing
stale state and interpreting it as valid completion data.

Fix this by freeing the pending work_data. The I2C transaction reports
an error. This ensures that failed requests do not leave residual state
behind that could be interpreted as valid RNG data on later reads.
Clearing rng->priv is done at the subsequent call to nonblocking read.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version da001fb651b00e1deeaf24767dd691ae8152a4f5
Version < a430b5b6d2ddd2b266330f8507a655be1148347d
Status affected
Version da001fb651b00e1deeaf24767dd691ae8152a4f5
Version < 4e76d85e505b7451925efbcd67c015e8c2440c68
Status affected
Version da001fb651b00e1deeaf24767dd691ae8152a4f5
Version < bcac9052e19490231ff6e0678a06bd2fcf8db3af
Status affected
Version da001fb651b00e1deeaf24767dd691ae8152a4f5
Version < 28cc179252347718f97045dd5ea74165609dbd7d
Status affected
Version da001fb651b00e1deeaf24767dd691ae8152a4f5
Version < 0d6db386133d9230befb77967bbf130443964860
Status affected
Version da001fb651b00e1deeaf24767dd691ae8152a4f5
Version < f4d347fb1309b69ea6f817a17e6b2893c8d754b7
Status affected
Version da001fb651b00e1deeaf24767dd691ae8152a4f5
Version < 94abda77b57a35b82bba0365bad072d94d67ffe9
Status affected
Version da001fb651b00e1deeaf24767dd691ae8152a4f5
Version < 72bbf11ba14bd7d5fbf31a1ec42fff608b657f74
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 5.3
Status affected
Version 0
Version < 5.3
Status unaffected
Version <= 5.10.*
Version 5.10.270
Status unaffected
Version <= 5.15.*
Version 5.15.221
Status unaffected
Version <= 6.1.*
Version 6.1.188
Status unaffected
Version <= 6.6.*
Version 6.6.157
Status unaffected
Version <= 6.12.*
Version 6.12.110
Status unaffected
Version <= 6.18.*
Version 6.18.52
Status unaffected
Version <= 7.2.*
Version 7.2.6
Status unaffected
Version <= *
Version 7.3-rc1
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.21% 0.116
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/a430b5b6d2ddd2b266330f8507a655be1148347d
https://git.kernel.org/stable/c/4e76d85e505b7451925efbcd67c015e8c2440c68
https://git.kernel.org/stable/c/bcac9052e19490231ff6e0678a06bd2fcf8db3af
https://git.kernel.org/stable/c/28cc179252347718f97045dd5ea74165609dbd7d
https://git.kernel.org/stable/c/0d6db386133d9230befb77967bbf130443964860
https://git.kernel.org/stable/c/f4d347fb1309b69ea6f817a17e6b2893c8d754b7
https://git.kernel.org/stable/c/94abda77b57a35b82bba0365bad072d94d67ffe9
https://git.kernel.org/stable/c/72bbf11ba14bd7d5fbf31a1ec42fff608b657f74