CVE-2026-93156

Summary

In the Linux kernel, the following vulnerability has been resolved:

crypto: rk3288 - fail ahash requests on HASH idle timeout

rk_hash_run() waits for RK_CRYPTO_HASH_STS to become idle after the final DMA transfer, but ignores the poll result. If the hash engine never becomes idle, the driver still reads the digest registers and finalizes the request with the previous success value.

Store the poll result and finalize the request with the timeout error before reading the digest registers.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux37bc22159c456ad43fb852fc6ed60f4081df25df < a22dc48d58ef46e21c0172ba83c33f1c9859e63caffected
LinuxLinux37bc22159c456ad43fb852fc6ed60f4081df25df < 2feb52b2796c25510903bf0f18a84cde44631391affected
LinuxLinux37bc22159c456ad43fb852fc6ed60f4081df25df < e7d8ddd471d2895f1d4098832c21121d4191adaaaffected
LinuxLinux37bc22159c456ad43fb852fc6ed60f4081df25df < 0a261177ad3245af393548d0632226d99c643191affected
LinuxLinux37bc22159c456ad43fb852fc6ed60f4081df25df < ae150db7826f21e8d19e54fb6243169628809c4daffected
LinuxLinux6.2affected
LinuxLinux0 < 6.2unaffected
LinuxLinux6.6.157 <= 6.6.*unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References