Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-93157

 

Improper Check or Handling of Exceptional Conditions in Linux kernel - CVE-2026-93157

Published: September 18, 2026


Vulnerability identifier: #VU150841
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-93157
CWE-ID: CWE-703
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to receive improperly collected random data.

The vulnerability exists due to improper handling of timeout errors and partial reads in the Xilinx TRNG driver when collecting random data from the hardware random-number generator. A local user can request random data to receive improperly collected random data.


Affected software

Linux kernel

How to mitigate CVE-2026-93157

Install security update from vendor's repository.


External References

Related Security Bulletins