Description
In the Linux kernel, the following vulnerability has been resolved:

crypto: atmel-ecc - reject hardware ECDH without a public key

The hardware ECDH path in atmel_ecdh_compute_shared_secret() uses the
private key stored in the device. However, the public key is cached only
after atmel_ecdh_set_secret() successfully generated that private key
for the current tfm.

atmel_ecdh_generate_public_key() already rejects requests when no public
key is cached. Add the same check to atmel_ecdh_compute_shared_secret()
to prevent the device from using a private key that was not generated
for the current tfm.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized use of cryptographic keys
Action: Apply Patch
AI Analysis

Impact

In the Linux kernel the atmel-ecdh driver was allowed to compute a shared secret using a private key that had not been generated for the current transformation object, because the check for a cached public key was missing in atmel_ecdh_compute_shared_secret(). This omission could enable the hardware ECDH path to use an outdated or unintended private key, potentially leaking cryptographic secrets or causing the algorithm to use incorrect keys. The flaw is a weakness in key management rather than a classic denial‑of‑service or code‑execution bug. It could undermine the confidentiality of communications that rely on this hardware ECDH implementation.

Affected Systems

All Linux kernel versions that contain the atmel-ecdh driver are affected. The issue is present in any kernel package that includes the "atmel_ecc" crypto driver before it was patched. Systems running a kernel with this driver and without the fix are at risk.

Risk and Exploitability

The EPSS score is reported as less than 1%, and the vulnerability is not listed in the CISA KEV catalog. No CVSS score is supplied. The flaw requires local access to the kernel to influence the cryptographic flow, so the likely attack vector is local or requires exploitation of a higher‑privilege vulnerability that grants kernel write capability. Given the low EPSS probability and lack of external exploitation evidence, the overall risk is moderate but should not be ignored. The vulnerability does not provide a direct path to remote code execution but could lead to a compromise of cryptographic confidentiality if the flaw is exploited by a privileged user.

Generated by OpenCVE AI on September 19, 2026 at 07:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply an updated Linux kernel that has incorporated the atmel‑ecc fix
  • If a patch cannot be applied immediately, disable or remove the atmel‑ecc driver until the kernel update is available
  • Monitor kernel logs for references to atmel_ecdh_compute_shared_secret() failures or incorrect key usage

Generated by OpenCVE AI on September 19, 2026 at 07:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-665

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: crypto: atmel-ecc - reject hardware ECDH without a public key The hardware ECDH path in atmel_ecdh_compute_shared_secret() uses the private key stored in the device. However, the public key is cached only after atmel_ecdh_set_secret() successfully generated that private key for the current tfm. atmel_ecdh_generate_public_key() already rejects requests when no public key is cached. Add the same check to atmel_ecdh_compute_shared_secret() to prevent the device from using a private key that was not generated for the current tfm.
Title crypto: atmel-ecc - reject hardware ECDH without a public key
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:54.517Z

Reserved: 2026-09-17T16:02:15.089Z

Link: CVE-2026-93160

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:11.407

Modified: 2026-09-17T17:18:11.407

Link: CVE-2026-93160

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:45:14Z

Weaknesses