Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-93159— crypto: atmel-sha204a - fix heap info leak on I2C transfer failure

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述信息的中文翻译: 在 Linux 内核中,已修复以下漏洞: crypto: atmel-sha204a - 修复 I2C 传输失败时的堆信息泄露 非阻塞随机数生成器(RNG)路径会分配一个 结构体,用于跟踪进行中的异步 I2C 请求状态。该指针存储在 中,并在事务完成后由读取路径使用。 如果底层的 I2C 传输失败,完成回调将以非零状态被调用。在这种情况下,已分配的 无法用于生成随机数输出,且不应再与硬件随机数生成器(hwrng)的状态保持关联。 此前,失败路径仅记录了一条警告,但未清除指针状态。这

AI Predicted 4.1 Difficulty: Hard EPSS 0.22% · P11

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux da001fb651b00e1deeaf24767dd691ae8152a4f5< a430b5b6d2ddd2b266330f8507a655be1148347d affected
da001fb651b00e1deeaf24767dd691ae8152a4f5< 4e76d85e505b7451925efbcd67c015e8c2440c68 affected
da001fb651b00e1deeaf24767dd691ae8152a4f5< bcac9052e19490231ff6e0678a06bd2fcf8db3af affected
da001fb651b00e1deeaf24767dd691ae8152a4f5< 28cc179252347718f97045dd5ea74165609dbd7d affected
da001fb651b00e1deeaf24767dd691ae8152a4f5< 0d6db386133d9230befb77967bbf130443964860 affected
da001fb651b00e1deeaf24767dd691ae8152a4f5< f4d347fb1309b69ea6f817a17e6b2893c8d754b7 affected
da001fb651b00e1deeaf24767dd691ae8152a4f5< 94abda77b57a35b82bba0365bad072d94d67ffe9 affected
da001fb651b00e1deeaf24767dd691ae8152a4f5< 72bbf11ba14bd7d5fbf31a1ec42fff608b657f74 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93159

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
crypto: atmel-sha204a - fix heap info leak on I2C transfer failure
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: crypto: atmel-sha204a - fix heap info leak on I2C transfer failure The nonblocking RNG path allocates a work_data structure to track the state of an in-flight asynchronous I2C request. This pointer is stored in rng->priv and later consumed by the read path once the transaction completes. If the underlying I2C transfer fails, the completion callback is invoked with a non-zero status. In this case, the allocated work_data is not usable for producing RNG output and must not remain associated with the hwrng state. Previously, the failure path only logged a warning but left the pointer state uncleared, which can result in subsequent read attempts observing stale state and interpreting it as valid completion data. Fix this by freeing the pending work_data. The I2C transaction reports an error. This ensures that failed requests do not leave residual state behind that could be interpreted as valid RNG data on later reads. Clearing rng->priv is done at the subsequent call to nonblocking read.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux da001fb651b00e1deeaf24767dd691ae8152a4f5 ~ a430b5b6d2ddd2b266330f8507a655be1148347d -
Linux Linux 5.3 -

II. Public POCs for CVE-2026-93159

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93159

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-93159 (8)

Same Patch Batch · Linux · 2026-09-17 · 600 CVEs total

CVE-2026-92489 9.8 CRITICAL xfrm: Fix skb double-free in xfrm_dev_direct_output()
CVE-2026-90151 9.8 CRITICAL NFSv4: remove callback IDR entry on client allocation failure
CVE-2026-90235 9.8 CRITICAL sunrpc: xprtsock: annotate shared socket callbacks with READ_ONCE/WRITE_ONCE
CVE-2026-90104 9.8 CRITICAL NFSv4.1: zero referring call lists before decoding
CVE-2026-90173 9.8 CRITICAL smb: smbdirect: free completion queues with ib_free_cq()
CVE-2026-90110 9.4 CRITICAL inetpeer: randomize RB-tree node comparison using SipHash
CVE-2026-90230 9.1 CRITICAL nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()
CVE-2026-90413 9.1 CRITICAL IB/isert: reject login PDUs declaring more data than was received
CVE-2026-90414 9.1 CRITICAL IB/isert: reject PDUs declaring more data than was received
CVE-2026-90425 8.8 HIGH iommu/tegra241-cmdqv: Require exactly one Stream ID for a vSID
CVE-2026-93042 8.8 HIGH dmaengine: dw-edma: Terminate all descriptors without callbacks
CVE-2026-93189 8.8 HIGH HID: core: quiesce input in hid_hw_stop() to prevent use-after-free
CVE-2026-90329 8.8 HIGH HID: synchronize input before cleaning up a failed probe
CVE-2026-90357 8.8 HIGH wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement
CVE-2026-90256 8.8 HIGH Bluetooth: L2CAP: use proto_lock for l2cap_data to fix l2cap_disconn_ind
CVE-2026-90367 8.8 HIGH wifi: mt76: mt7996: hold dev->mt76.mutex while disabling tx worker in SER
CVE-2026-90381 8.8 HIGH wifi: mt76: fix handling channel context with different bands in mt76_switch_vif_chanctx()
CVE-2026-90379 8.8 HIGH wifi: mt76: mt7921: Add PCIe AER handler support to prevent system crash
CVE-2026-90380 8.8 HIGH wifi: mt76: mt792x: fix use-after-free in mt76_rx_poll_complete
CVE-2026-90371 8.8 HIGH wifi: mt76: fix RXDMAD_C buffer recycling race

Showing top 20 of 600 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-93159

No comments yet


Leave a comment