Description
In the Linux kernel, the following vulnerability has been resolved:

crypto: atmel-sha204a - fix heap info leak on I2C transfer failure

The nonblocking RNG path allocates a work_data structure to track the
state of an in-flight asynchronous I2C request. This pointer is stored
in rng->priv and later consumed by the read path once the transaction
completes.

If the underlying I2C transfer fails, the completion callback is invoked
with a non-zero status. In this case, the allocated work_data is not
usable for producing RNG output and must not remain associated with the
hwrng state.

Previously, the failure path only logged a warning but left the pointer
state uncleared, which can result in subsequent read attempts observing
stale state and interpreting it as valid completion data.

Fix this by freeing the pending work_data. The I2C transaction reports
an error. This ensures that failed requests do not leave residual state
behind that could be interpreted as valid RNG data on later reads.
Clearing rng->priv is done at the subsequent call to nonblocking read.
Published: 2026-09-17
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Exposure via stale RNG data
Action: Patch
AI Analysis

Impact

In the Linux kernel’s crypto atmel‑sha204a driver, an error in an I2C transfer used by the nonblocking random number generator path can leave a stale work_data structure pointer in router state. When the transfer fails, the callback logs a warning but fails to clear the pointer. Subsequent RNG reads may interpret this leftover data as valid, effectively leaking information that could reveal aspects of the device’s random number generator state. This constitutes an information exposure problem rather than a denial or compromise of integrity. The vulnerability is only exploitable when an attacker can deliberately trigger I2C failures on the targeted hardware, which typically requires local or privileged access to the device or the ability to cause bus errors.

Affected Systems

Linux kernel configurations that use the atmel‑sha204a driver. All kernel versions before the fix that include the default device driver are impacted; specific version numbers are not enumerated in the advisory.

Risk and Exploitability

The anomaly is not listed in CISA’s KEV catalog and the EPSS score is less than 1%, indicating a low probability of exploitation in the wild. The CVSS score of 5.5 indicates a moderate severity. The potential impact is confidentiality loss of RNG output, which could reduce entropy for cryptographic operations on the affected system. While exploitation requires an I2C bus error or induced hardware failure, the vulnerability shows that an attacker with sufficient local access could repeatedly cause failures to accumulate and read the stale state. Overall, the risk is moderate given the low exploitation likelihood but significant confidentiality impact if exploited.

Generated by OpenCVE AI on September 22, 2026 at 01:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the kernel patch that frees the pending work_data and clears rng->priv on I2C transfer failure.
  • Reboot the system after applying the patch to ensure any residual state is reset and that the RNG driver starts fresh.
  • Continuously monitor I2C bus error logs and RNG output patterns; if anomalous or repeated failures appear, investigate possible hardware faults or unauthorized manipulation.

Generated by OpenCVE AI on September 22, 2026 at 01:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Tue, 22 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-459
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-200

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: crypto: atmel-sha204a - fix heap info leak on I2C transfer failure The nonblocking RNG path allocates a work_data structure to track the state of an in-flight asynchronous I2C request. This pointer is stored in rng->priv and later consumed by the read path once the transaction completes. If the underlying I2C transfer fails, the completion callback is invoked with a non-zero status. In this case, the allocated work_data is not usable for producing RNG output and must not remain associated with the hwrng state. Previously, the failure path only logged a warning but left the pointer state uncleared, which can result in subsequent read attempts observing stale state and interpreting it as valid completion data. Fix this by freeing the pending work_data. The I2C transaction reports an error. This ensures that failed requests do not leave residual state behind that could be interpreted as valid RNG data on later reads. Clearing rng->priv is done at the subsequent call to nonblocking read.
Title crypto: atmel-sha204a - fix heap info leak on I2C transfer failure
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:53.852Z

Reserved: 2026-09-17T16:02:15.089Z

Link: CVE-2026-93159

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:11.277

Modified: 2026-09-17T17:18:11.277

Link: CVE-2026-93159

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-17T00:00:00Z

Links: CVE-2026-93159 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T01:30:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-459

    Incomplete Cleanup