Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-80922— crypto: qcom-rng - Allow zero as a random number

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,已修复以下漏洞: crypto: qcom-rng - 允许零作为随机数 零是一个有效的随机数,必须被允许。否则,输出将与真正的随机数存在可区分性。

AI Predicted 3.7 Difficulty: Theoretical

Possible ATT&CK Techniques 1 AI

T1562.001

Affected Version Matrix 12

VendorProduct Version RangeStatus
Linux Linux f29cd5bb64c258f29b4c49452532481f50eb43ca< 813e6718a199befc4f26f54bdd899fbfa11515e5 affected
f29cd5bb64c258f29b4c49452532481f50eb43ca< 4c0018320942003bfedd0a1c4cce3f036d363a7f affected
f29cd5bb64c258f29b4c49452532481f50eb43ca< 143c74034a1c47b0a1a64e7ca7153e7739bd1244 affected
f29cd5bb64c258f29b4c49452532481f50eb43ca< 3c7101cfc52e378bcb0a46962145e39c9051dd5d affected
f29cd5bb64c258f29b4c49452532481f50eb43ca< 4ef04bdc0c9f98836d1638be516f6bf1bad55f69 affected
6.7 affected
< 6.7 unaffected
6.12.108≤ 6.12.* unaffected
… +4 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80922

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
crypto: qcom-rng - Allow zero as a random number
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - Allow zero as a random number Zero is a valid random number and needs to be allowed. Otherwise the output is distinguishable from random.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux f29cd5bb64c258f29b4c49452532481f50eb43ca ~ 813e6718a199befc4f26f54bdd899fbfa11515e5 -
Linux Linux 6.7 -

II. Public POCs for CVE-2026-80922

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80922

登录查看更多情报信息。

Patches & Fixes for CVE-2026-80922 (5)

Same Patch Batch · Linux · 2026-09-09 · 12 CVEs total

CVE-2026-80925 vlan: fix skb_under_panic and races when toggling HW VLAN offload
CVE-2026-80924 crypto: krb5 - use kfree_sensitive() for derived key buffers
CVE-2026-80923 xhci: dbgtty: Fix unregister on tty_register_driver() failure
CVE-2026-80921 KVM: s390: vsie: zero stale crypto bits
CVE-2026-80920 io_uring: defer eventfd signaling when queued from a wakeup handler
CVE-2026-80919 drm/amdgpu: fix recursive ww_mutex acquire in amdgpu_devcoredump_format
CVE-2026-80918 HID: core: fix number/pointer type confusion on long items
CVE-2026-80917 PCI: host-generic: Fix NULL pointer dereference on 32-bit CAM systems
CVE-2026-80916 kcov: fix data corruption and race conditions on PREEMPT_RT
CVE-2026-80915 drm/xe: Fix DPT allocation paths.
CVE-2026-80914 Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready

IV. Related Vulnerabilities

V. Comments for CVE-2026-80922

No comments yet


Leave a comment