SB2026091848 - Improper Check or Handling of Exceptional Conditions in Linux kernel char hw_random driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper Check or Handling of Exceptional Conditions (CVE-ID: CVE-2026-93157)
CWE-ID: CWE-703 - Improper Check or Handling of Exceptional Conditions
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to receive improperly collected random data.
The vulnerability exists due to improper handling of timeout errors and partial reads in the Xilinx TRNG driver when collecting random data from the hardware random-number generator. A local user can request random data to receive improperly collected random data.
Remediation
Install update from vendor's website.