SB20260905119 - Race condition in Linux kernel crypto driver
Published: September 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Race condition (CVE-ID: CVE-2026-80835)
CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause repeated or non-random random-number output.
The vulnerability exists due to improper synchronization in the Qualcomm RNG driver when concurrently using the crypto_rng and hwrng interfaces. A local user can issue concurrent random-number generation operations to cause repeated or non-random random-number output.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/14d9ee8286460a7b82f3b8610b5c7ebf4550b06b
- https://git.kernel.org/stable/c/2ecdf5c9910e20f73639bc322f0518a3439d17c0
- https://git.kernel.org/stable/c/669d940351eda316b82e24986e2e0e057653ce7d
- https://git.kernel.org/stable/c/843e2bdaf8deb8bc341203094dfe582e38ea4af2
- https://git.kernel.org/stable/c/bb474dcd9d0224264a27a60891f00872b879835f