Return of Wrong Status Code in Linux kernel - CVE-2026-80871
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to cause cryptographic operations to receive incomplete random data.
The vulnerability exists due to an incorrect success status return in xtrng_trng_generate() when generating random bytes through the crypto_rng interface. A local user can invoke the crypto_rng interface to cause cryptographic operations to receive incomplete random data.