CVE-2026-80922

Summary

In the Linux kernel, the following vulnerability has been resolved:

crypto: qcom-rng - Allow zero as a random number

Zero is a valid random number and needs to be allowed. Otherwise the output is distinguishable from random.

Affected Software

VendorProductVersion RangeStatus
LinuxLinuxf29cd5bb64c258f29b4c49452532481f50eb43ca < 813e6718a199befc4f26f54bdd899fbfa11515e5affected
LinuxLinuxf29cd5bb64c258f29b4c49452532481f50eb43ca < 4c0018320942003bfedd0a1c4cce3f036d363a7faffected
LinuxLinuxf29cd5bb64c258f29b4c49452532481f50eb43ca < 143c74034a1c47b0a1a64e7ca7153e7739bd1244affected
LinuxLinuxf29cd5bb64c258f29b4c49452532481f50eb43ca < 3c7101cfc52e378bcb0a46962145e39c9051dd5daffected
LinuxLinuxf29cd5bb64c258f29b4c49452532481f50eb43ca < 4ef04bdc0c9f98836d1638be516f6bf1bad55f69affected
LinuxLinux6.7affected
LinuxLinux0 < 6.7unaffected
LinuxLinux6.12.108 <= 6.12.*unaffected
LinuxLinux6.18.49 <= 6.18.*unaffected
LinuxLinux7.1.13 <= 7.1.*unaffected
LinuxLinux7.2.3 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References