Impact
The Linux kernel’s hwrng driver for Xilinx TRNG incorrectly propagates a poll timeout, causing the driver to return a number of bytes read even when no data is available. The caller interprets a zero return as a short successful read, so partial data is used as if the full 32‑byte block had been obtained. This flaw reduces the entropy of the random data provided by the kernel, potentially allowing an attacker to predict the output of the RNG and compromise cryptographic operations that rely on it.
Affected Systems
All Linux kernel builds that include the xilinx-trng hwrng driver are affected, regardless of the specific kernel version. The vulnerability exists until the upstream patch is applied to the kernel source tree.
Risk and Exploitability
The CVSS score is not listed here, but the EPSS score is less than 1 % and the issue is not in the CISA KEV catalog, suggesting a low overall exploitation probability. The flaw requires local access or the ability to load a modified driver, meaning it is not exploitable from the network. Nevertheless, any system that uses the affected TRNG source for critical cryptographic key generation or random data production faces a risk that the quality of entropy is degraded, which could lead to predictable keys or nonce reuse.
OpenCVE Enrichment