Description
In the Linux kernel, the following vulnerability has been resolved:

crypto: keembay - Initialize completion before requesting IRQ

kmb_ocs_aes_probe() requests the device IRQ before initializing
irq_completion. Once the handler is registered it can run immediately,
and ocs_aes_irq_handler() unconditionally calls complete(). An
interrupt in this window would therefore use an uninitialized
completion.

Initialize the completion before requesting the IRQ, as the sibling
OCS HCU and ECC drivers already do.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

A bug in the Linux kernel cryptographic driver "keembay" causes a completion object to be used before it is initialized. When an IRQ is requested while the completion is still uninitialized, an interrupt can be delivered to the handler, which calls complete() on an uninitialized object. This leads to undefined behavior, typically a deadlock or corruption of synchronization state, that can prevent normal kernel operation and result in a denial of service.

Affected Systems

The flaw resides in the Linux kernel itself; no specific kernel release is listed in the advisory. Any Linux distribution using a kernel build that includes the keembay driver before the patch is potentially affected.

Risk and Exploitability

The exploitability of this issue is low. The EPSS score is reported as less than 1 %, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attacking would require triggering an interrupt during the narrow window when the IRQ is registered but the completion remains uninitialized, a scenario that typically demands kernel‑level privileges or physical access. The primary consequence is a potential denial of service by interrupt‑handling failure rather than remote code execution or data exfiltration.

Generated by OpenCVE AI on September 19, 2026 at 05:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Linux kernel update that initializes the completion before requesting the IRQ.
  • If an immediate kernel upgrade is not feasible, disable or remove the keembay module until the patch can be applied.
  • In custom kernel modules, ensure that completion objects are initialized before any IRQ registration to prevent similar race conditions.

Generated by OpenCVE AI on September 19, 2026 at 05:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: crypto: keembay - Initialize completion before requesting IRQ kmb_ocs_aes_probe() requests the device IRQ before initializing irq_completion. Once the handler is registered it can run immediately, and ocs_aes_irq_handler() unconditionally calls complete(). An interrupt in this window would therefore use an uninitialized completion. Initialize the completion before requesting the IRQ, as the sibling OCS HCU and ECC drivers already do.
Title crypto: keembay - Initialize completion before requesting IRQ
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:09:55.083Z

Reserved: 2026-09-16T12:21:13.869Z

Link: CVE-2026-92476

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:17:49.593

Modified: 2026-09-17T17:17:49.593

Link: CVE-2026-92476

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T10:30:16Z

Weaknesses

No weakness.