SB2026091849 - Unchecked Return Value in Linux kernel crypto driver
Published: September 18, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Unchecked Return Value (CVE-ID: CVE-2026-93158)
CWE-ID: CWE-252 - Unchecked Return Value
CVSSv4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause crypto request setup failures.
The vulnerability exists due to unchecked return value handling in sa_ul_probe() when security-context DMA pool creation fails. A local user can initiate use of the driver after DMA pool creation fails to cause crypto request setup failures.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/04c46784ec249cac995e31f0691397b82bdaa5fd
- https://git.kernel.org/stable/c/304dcd26bfc3ce6771c2bd3b7c0299dcfd5f4e06
- https://git.kernel.org/stable/c/91ded4742fcde6ad415c4d8a20e5ea0dcdf4f73e
- https://git.kernel.org/stable/c/9907426b438e4dbc8c45138bd440ad6d732d80b7
- https://git.kernel.org/stable/c/9a692a6a2b47328a36c8d80c7fbf81da16b6d6b1
- https://git.kernel.org/stable/c/b68b35ed97d3e18edb9dea500d88420a95006742
- https://git.kernel.org/stable/c/d03f980a25853f6a380895119a572a3bb1194e8d
- https://git.kernel.org/stable/c/f72c7837614a9705f8b3021828d49c9f095803ba