CVE-2026-93163

Summary

In the Linux kernel, the following vulnerability has been resolved:

hwrng: core - fix rng list on registration error

hwrng_register(rng) does the following:

  1. Checks if rng has name and read methods set
  2. Checks if the name already exists
  3. Adds rng to global rng_list
  4. May try to set rng to current_rng

If step 4 fails, it returns an error. However, it does not remove the rng from rng_list, causing a dangling reference which can result in use-after-free if the caller frees rng, since registration failed.

Add a list_del_init() cleanup step.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux2bbb6983887fefc8026beab01198d30f47b7bd22 < de4f1bcb61a73cc896decdbd27d61a34add93b53affected
LinuxLinux2bbb6983887fefc8026beab01198d30f47b7bd22 < cf293c9c7424de0d04b51367d07f40570ce80231affected
LinuxLinux2bbb6983887fefc8026beab01198d30f47b7bd22 < bee8d1fcdc8f389b595b0a4cf6fe8440f499458aaffected
LinuxLinux2bbb6983887fefc8026beab01198d30f47b7bd22 < 3a5834db2b1ce25649f330e78efe1ccde78967fdaffected
LinuxLinux42802952a2725f85f7e36ee3b29593af5fe87197affected
LinuxLinux4.9.320 < 4.10affected
LinuxLinux4.14affected
LinuxLinux0 < 4.14unaffected
LinuxLinux6.12.110 <= 6.12.*unaffected
LinuxLinux6.18.52 <= 6.18.*unaffected
LinuxLinux7.2.6 <= 7.2.*unaffected
LinuxLinux7.3-rc1 <= *unaffected

Weaknesses

References