Unchecked Return Value in Linux kernel - CVE-2026-93158
Published: September 18, 2026
Vulnerability identifier: #VU150842
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-93158
CWE-ID: CWE-252
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to cause crypto request setup failures.
The vulnerability exists due to unchecked return value handling in sa_ul_probe() when security-context DMA pool creation fails. A local user can initiate use of the driver after DMA pool creation fails to cause crypto request setup failures.
Affected software
Linux kernel
How to mitigate CVE-2026-93158
Install security update from vendor's repository.
Linux kernel - update to 7.0 rc3
External References
- https://git.kernel.org/stable/c/04c46784ec249cac995e31f0691397b82bdaa5fd
- https://git.kernel.org/stable/c/304dcd26bfc3ce6771c2bd3b7c0299dcfd5f4e06
- https://git.kernel.org/stable/c/91ded4742fcde6ad415c4d8a20e5ea0dcdf4f73e
- https://git.kernel.org/stable/c/9907426b438e4dbc8c45138bd440ad6d732d80b7
- https://git.kernel.org/stable/c/9a692a6a2b47328a36c8d80c7fbf81da16b6d6b1
- https://git.kernel.org/stable/c/b68b35ed97d3e18edb9dea500d88420a95006742
- https://git.kernel.org/stable/c/d03f980a25853f6a380895119a572a3bb1194e8d
- https://git.kernel.org/stable/c/f72c7837614a9705f8b3021828d49c9f095803ba