Improper locking in Linux kernel - CVE-2026-80871
Published: September 5, 2026
Vulnerability details
The vulnerability allows a local user to cause concurrent accesses to the TRNG device to interfere with each other.
The vulnerability exists due to improper locking in xtrng_hwrng_trng_read() when crypto_rng generation and hwrng reads run concurrently. A local user can trigger concurrent crypto_rng generation and hwrng read operations to cause concurrent accesses to the TRNG device to interfere with each other.