VYPR
Unrated severityNVD Advisory· Published Sep 17, 2026

CVE-2026-93163

CVE-2026-93163

Description

In the Linux kernel, the following vulnerability has been resolved:

hwrng: core - fix rng list on registration error

hwrng_register(rng) does the following:

  1. Checks if rng has name and read methods set
  2. Checks if the name already exists
  3. Adds rng to global rng_list
  4. May try to set rng to current_rng

If step 4 fails, it returns an error. However, it does not remove the rng from rng_list, causing a dangling reference which can result in use-after-free if the caller frees rng, since registration failed.

Add a list_del_init() cleanup step.

Affected products

2

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.