Description
In the Linux kernel, the following vulnerability has been resolved:

crypto: qcom-rng - Allow zero as a random number

Zero is a valid random number and needs to be allowed. Otherwise the
output is distinguishable from random.
Published: 2026-09-09
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Collision of randomness due to forbidden zero
Action: Apply patch
AI Analysis

Impact

The Linux kernel’s qcom-rng random number generator mistakenly rejects zero, making the stream detectable as non‑random. This flaw does not leak secrets directly, but it introduces a statistical bias that could allow an adversary to distinguish the output from a true random source and therefore infer properties of the RNG state or subsequent data derived from it.

Affected Systems

This issue affects the generic Linux kernel implementation, specifically the qcom-rng module. No explicit version numbers are provided, but the vulnerability was fixed in a recent kernel commit. The affected vendor/product identifiers are Linux:Linux.

Risk and Exploitability

Because the flaw only impacts the statistical distribution of generated numbers, the direct exploitation surface is limited. No exploit probability (EPSS) is reported and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is also absent from the data, so the exact severity cannot be quantified. The likely attack vector would involve an attacker with a need to identify subtle RNG weaknesses, for example in cryptographic protocols that rely on perfect randomness, though practical impact is uncertain without further context.

Generated by OpenCVE AI on September 9, 2026 at 17:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version containing the qcom‑rng patch (commit 143c74034a1c47b0a1a64e7ca7153e7739bd1244 or newer).
  • Replace or disable the qcom‑rng module and use a vetted alternative random source such as /dev/urandom or the entropy pool exposed by the kernel.
  • After updating, verify that the qcom‑rng driver accepts zero as a valid return value by inspecting its output or using a randomness test suite.

Generated by OpenCVE AI on September 9, 2026 at 17:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Wed, 09 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-332

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: crypto: qcom-rng - Allow zero as a random number Zero is a valid random number and needs to be allowed. Otherwise the output is distinguishable from random.
Title crypto: qcom-rng - Allow zero as a random number
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-09T16:19:42.937Z

Reserved: 2026-08-26T14:34:25.801Z

Link: CVE-2026-80922

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-09T17:17:47.383

Modified: 2026-09-09T17:17:47.383

Link: CVE-2026-80922

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T19:45:08Z

Weaknesses
  • CWE-332

    Insufficient Entropy in PRNG