Description
In the Linux kernel, the following vulnerability has been resolved:

hwrng: core - fix rng list on registration error

hwrng_register(rng) does the following:

1. Checks if rng has name and read methods set
2. Checks if the name already exists
3. Adds rng to global rng_list
4. May try to set rng to current_rng

If step 4 fails, it returns an error. However, it does not remove the
rng from rng_list, causing a dangling reference which can result in
use-after-free if the caller frees rng, since registration failed.

Add a list_del_init() cleanup step.
Published: 2026-09-17
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Use‑After‑Free
Action: Apply Patch
AI Analysis

Impact

The Linux kernel’s hardware random number generator registration routine fails to remove a device from the global list when a later step of the initialization process fails, leaving the list referencing a freed object. This dangling reference can lead to a use‑after‑free condition if code that called the registration routine frees the object after the error is returned. An attacker who can influence the registration sequence or the object’s lifetime could trigger the use‑after‑free to execute arbitrary code in kernel mode, potentially escalating privileges. The weakness is a classic instance of code not cleaning up state on error, allowing a memory reference to be used after the pointed‑to object has been deallocated.

Affected Systems

The flaw resides in the core Linux kernel code common to all distributions. Any system running an affected kernel version without the applied fix is vulnerable. No specific kernel versions are listed in the data, so all unpatched kernels could be impacted.

Risk and Exploitability

The EPSS score is reported as less than 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a very low probability of public exploitation. A use‑after‑free in kernel space typically yields a high severity if successfully exploited, requiring local or elevated privileges. Without a local kernel exploit or a way to inject code through an external interface, the practical risk remains low.

Generated by OpenCVE AI on September 19, 2026 at 08:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the kernel to a version that includes the hwrng register cleanup fix
  • Reboot the system to activate the updated kernel image
  • Disable the hwrng subsystem on systems that cannot be updated immediately

Generated by OpenCVE AI on September 19, 2026 at 08:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4817-1 linux-6.12 security update
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Sat, 19 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-416

Thu, 17 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: hwrng: core - fix rng list on registration error hwrng_register(rng) does the following: 1. Checks if rng has name and read methods set 2. Checks if the name already exists 3. Adds rng to global rng_list 4. May try to set rng to current_rng If step 4 fails, it returns an error. However, it does not remove the rng from rng_list, causing a dangling reference which can result in use-after-free if the caller frees rng, since registration failed. Add a list_del_init() cleanup step.
Title hwrng: core - fix rng list on registration error
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-17T16:11:56.570Z

Reserved: 2026-09-17T16:02:15.089Z

Link: CVE-2026-93163

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-17T17:18:11.763

Modified: 2026-09-17T17:18:11.763

Link: CVE-2026-93163

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T18:45:14Z

Weaknesses