Description
In the Linux kernel, the following vulnerability has been resolved:

crypto: rk3288 - fail ahash requests on HASH idle timeout

rk_hash_run() waits for RK_CRYPTO_HASH_STS to become idle after the
final DMA transfer, but ignores the poll result. If the hash engine
never becomes idle, the driver still reads the digest registers and
finalizes the request with the previous success value.

Store the poll result and finalize the request with the timeout error
before reading the digest registers.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Return of stale hash value due to failure to detect timeout
Action: Apply Patch
AI Analysis

Impact

The vulnerability in the Linux kernel's rk3288 crypto driver causes ahash requests to incorrectly finalize when the hardware hash engine fails to become idle within an expected timeout. The driver ignores the timeout poll result, reads stale digest registers, and reports a previous successful hash value. This flaw can lead to an unauthorized user receiving a valid hash for data that was not actually processed, potentially undermining cryptographic integrity checks or authentication mechanisms that depend on accurate hash results. The weakness aligns with CWE-676 and CWE-368, reflecting incorrect error handling and misuse of stale data.

Affected Systems

The affected product is the Linux kernel, as identified by the Linux:Linux CNA vendor entry. All kernel versions before the fix described in the linked commits are vulnerable; specific version ranges are not specified. Kernel CPE strings indicate the flaw exists across the broader Linux kernel ecosystem.

Risk and Exploitability

The EPSS score is less than 1%, suggesting very low probability of exploitation in the wild, and the vulnerability has not been listed in the CISA KEV catalog. Without a CVSS score, the severity is unclear, but the flaw permits misuse of cryptographic results, which could have non‑repudiation or integrity impacts in systems that rely on the rk3288 crypto engine. The likely attack vector is a local privilege escalation or a user with the ability to invoke cryptographic hash operations on the affected device, inferred from the nature of driver operations. No publicly documented exploitation exploits are indicated, and the risk appears limited to environments that use the rk3288 crypto hardware without additional safety checks.

Generated by OpenCVE AI on September 19, 2026 at 07:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that addresses the timeout handling in rk_hash_run, available in the commit references.
  • Confirm the driver module reflects the fixed code by checking its version or commit hash.
  • Disable or replace the rk3288 crypto driver if the system can operate using software hashing to avoid the issue.

Generated by OpenCVE AI on September 19, 2026 at 07:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-368
CWE-676

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: crypto: rk3288 - fail ahash requests on HASH idle timeout rk_hash_run() waits for RK_CRYPTO_HASH_STS to become idle after the final DMA transfer, but ignores the poll result. If the hash engine never becomes idle, the driver still reads the digest registers and finalizes the request with the previous success value. Store the poll result and finalize the request with the timeout error before reading the digest registers.
Title crypto: rk3288 - fail ahash requests on HASH idle timeout
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:51.461Z

Reserved: 2026-09-17T16:02:15.089Z

Link: CVE-2026-93156

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:10.927

Modified: 2026-09-17T17:18:10.927

Link: CVE-2026-93156

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:45:14Z

Weaknesses
  • CWE-368

    Context Switching Race Condition

  • CWE-676

    Use of Potentially Dangerous Function