Impact
In the Linux kernel’s crypto atmel‑sha204a driver, an error in an I2C transfer used by the nonblocking random number generator path can leave a stale work_data structure pointer in router state. When the transfer fails, the callback logs a warning but fails to clear the pointer. Subsequent RNG reads may interpret this leftover data as valid, effectively leaking information that could reveal aspects of the device’s random number generator state. This constitutes an information exposure problem rather than a denial or compromise of integrity. The vulnerability is only exploitable when an attacker can deliberately trigger I2C failures on the targeted hardware, which typically requires local or privileged access to the device or the ability to cause bus errors.
Affected Systems
Linux kernel configurations that use the atmel‑sha204a driver. All kernel versions before the fix that include the default device driver are impacted; specific version numbers are not enumerated in the advisory.
Risk and Exploitability
The anomaly is not listed in CISA’s KEV catalog and the EPSS score is less than 1%, indicating a low probability of exploitation in the wild. The CVSS score of 5.5 indicates a moderate severity. The potential impact is confidentiality loss of RNG output, which could reduce entropy for cryptographic operations on the affected system. While exploitation requires an I2C bus error or induced hardware failure, the vulnerability shows that an attacker with sufficient local access could repeatedly cause failures to accumulate and read the stale state. Overall, the risk is moderate given the low exploitation likelihood but significant confidentiality impact if exploited.
OpenCVE Enrichment
Debian DLA
Debian DSA