Impact
In the Linux kernel the atmel-ecdh driver was allowed to compute a shared secret using a private key that had not been generated for the current transformation object, because the check for a cached public key was missing in atmel_ecdh_compute_shared_secret(). This omission could enable the hardware ECDH path to use an outdated or unintended private key, potentially leaking cryptographic secrets or causing the algorithm to use incorrect keys. The flaw is a weakness in key management rather than a classic denial‑of‑service or code‑execution bug. It could undermine the confidentiality of communications that rely on this hardware ECDH implementation.
Affected Systems
All Linux kernel versions that contain the atmel-ecdh driver are affected. The issue is present in any kernel package that includes the "atmel_ecc" crypto driver before it was patched. Systems running a kernel with this driver and without the fix are at risk.
Risk and Exploitability
The EPSS score is reported as less than 1%, and the vulnerability is not listed in the CISA KEV catalog. No CVSS score is supplied. The flaw requires local access to the kernel to influence the cryptographic flow, so the likely attack vector is local or requires exploitation of a higher‑privilege vulnerability that grants kernel write capability. Given the low EPSS probability and lack of external exploitation evidence, the overall risk is moderate but should not be ignored. The vulnerability does not provide a direct path to remote code execution but could lead to a compromise of cryptographic confidentiality if the flaw is exploited by a privileged user.
OpenCVE Enrichment
Debian DLA
Debian DSA