CVE-2026-93157
In the Linux kernel, the following vulnerability has been resolved: hwrng: xilinx-trng - propagate timeout before any data is read xtrng_readblock32() polls for 16-byte chunks but returns the number of bytes read even when the first poll times out. Its caller then treats a zero return as a short successful read, and partial reads for full 32-byte blocks can make the tail copy use a fixed block offset rather than the amount already produced. Return the poll error when no data has been read, preserve partial positive returns after some data is available, stop the generator on all collection exits, and append tail bytes at the current output count.
Affected versions
Linux kernel versions
6.18
and later are affected. Fixed in
6.18.52,
7.2.6,
7.3-rc1
and their respective stable series.
References
3 totalFrequently asked questions
-
What is CVE-2026-93157?
CVE-2026-93157 is a unscored severity Linux kernel vulnerability . It affects Linux kernel versions from 6.18 onward and has been patched in 6.18.52, 7.2.6 and 7.3-rc1. CVE-2026-93157 has not been confirmed as actively exploited and is not listed in the CISA KEV catalog.
-
Is there a patch available for CVE-2026-93157?
Yes. CVE-2026-93157 has been patched. Fixed versions include 6.18.52, 7.2.6 and 7.3-rc1. If you are running Linux kernel 6.18 or later up to the fix versions, apply the relevant patch for your kernel branch.
-
Is CVE-2026-93157 actively exploited?
No. CVE-2026-93157 has not been confirmed as actively exploited. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.