SB2026091848 - Improper Check or Handling of Exceptional Conditions in Linux kernel char hw_random driver



SB2026091848 - Improper Check or Handling of Exceptional Conditions in Linux kernel char hw_random driver

Published: September 18, 2026

Security Bulletin ID SB2026091848
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-93157)

CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions

CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to receive improperly collected random data.

The vulnerability exists due to improper handling of timeout errors and partial reads in the Xilinx TRNG driver when collecting random data from the hardware random-number generator. A local user can request random data to receive improperly collected random data.


Remediation

Install update from vendor's website.