Description
In the Linux kernel, the following vulnerability has been resolved:

hwrng: xilinx-trng - propagate timeout before any data is read

xtrng_readblock32() polls for 16-byte chunks but returns the number of
bytes read even when the first poll times out. Its caller then treats a
zero return as a short successful read, and partial reads for full
32-byte blocks can make the tail copy use a fixed block offset rather
than the amount already produced.

Return the poll error when no data has been read, preserve partial
positive returns after some data is available, stop the generator on all
collection exits, and append tail bytes at the current output count.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Weak random number generator due to improper timeout handling
Action: Immediate Patch
AI Analysis

Impact

The Linux kernel’s hwrng driver for Xilinx TRNG incorrectly propagates a poll timeout, causing the driver to return a number of bytes read even when no data is available. The caller interprets a zero return as a short successful read, so partial data is used as if the full 32‑byte block had been obtained. This flaw reduces the entropy of the random data provided by the kernel, potentially allowing an attacker to predict the output of the RNG and compromise cryptographic operations that rely on it.

Affected Systems

All Linux kernel builds that include the xilinx-trng hwrng driver are affected, regardless of the specific kernel version. The vulnerability exists until the upstream patch is applied to the kernel source tree.

Risk and Exploitability

The CVSS score is not listed here, but the EPSS score is less than 1 % and the issue is not in the CISA KEV catalog, suggesting a low overall exploitation probability. The flaw requires local access or the ability to load a modified driver, meaning it is not exploitable from the network. Nevertheless, any system that uses the affected TRNG source for critical cryptographic key generation or random data production faces a risk that the quality of entropy is degraded, which could lead to predictable keys or nonce reuse.

Generated by OpenCVE AI on September 19, 2026 at 07:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version in which the xilinx-trng hwrng driver has been patched for timeout handling
  • If possible, temporarily disable or remove use of the Xilinx TRNG source until the patch is applied, relying on a known‑good entropy source in the meantime
  • After updating, verify that the RNG provides full 32‑byte blocks without timeout errors by monitoring the kernel logs or using tools such as rng-tools or /proc/randstate

Generated by OpenCVE AI on September 19, 2026 at 07:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: hwrng: xilinx-trng - propagate timeout before any data is read xtrng_readblock32() polls for 16-byte chunks but returns the number of bytes read even when the first poll times out. Its caller then treats a zero return as a short successful read, and partial reads for full 32-byte blocks can make the tail copy use a fixed block offset rather than the amount already produced. Return the poll error when no data has been read, preserve partial positive returns after some data is available, stop the generator on all collection exits, and append tail bytes at the current output count.
Title hwrng: xilinx-trng - propagate timeout before any data is read
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:52.459Z

Reserved: 2026-09-17T16:02:15.089Z

Link: CVE-2026-93157

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:11.040

Modified: 2026-09-17T17:18:11.040

Link: CVE-2026-93157

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T08:30:16Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure