crypto: qat - clear AES key schedule from stack
Summary
| CVE | CVE-2026-93161 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-17 17:18:11 UTC |
| Updated | 2026-09-17 17:18:11 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: crypto: qat - clear AES key schedule from stack qat_alg_xts_reverse_key() expands the forward XTS AES key on the stack. That schedule contains key material and can remain in the stack frame. Clear the temporary crypto_aes_ctx with memzero_explicit() after the copy. |
Risk And Classification
EPSS: 0.002060000 probability, percentile 0.109900000 (date 2026-09-18)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 5106dfeaeabea73d5132daab1d89d57b57fa98b7 b9cf42622b30178f554fa74411eec67e02d70411 git | Not specified |
| CNA | Linux | Linux | affected 5106dfeaeabea73d5132daab1d89d57b57fa98b7 fb1194b78a163cc56bb9480c707fc34b53522359 git | Not specified |
| CNA | Linux | Linux | affected 5106dfeaeabea73d5132daab1d89d57b57fa98b7 892f34dc1819cceb8841005a68086710ce3763b6 git | Not specified |
| CNA | Linux | Linux | affected 5106dfeaeabea73d5132daab1d89d57b57fa98b7 dcaa0f1e86cbcb01f68131ae907b54cf299a3592 git | Not specified |
| CNA | Linux | Linux | affected 5106dfeaeabea73d5132daab1d89d57b57fa98b7 9af019e213ada5c3d0d33c515071a1414b6899f3 git | Not specified |
| CNA | Linux | Linux | affected 5106dfeaeabea73d5132daab1d89d57b57fa98b7 92e4979e1a770860b26aa3d90cce0c4c6a53833c git | Not specified |
| CNA | Linux | Linux | affected 5106dfeaeabea73d5132daab1d89d57b57fa98b7 d41a9fcfb7f9ee36e4a4aaf5e7996bca6be1e7a9 git | Not specified |
| CNA | Linux | Linux | affected 5.11 | Not specified |
| CNA | Linux | Linux | unaffected 5.11 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.221 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.188 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.157 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.110 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.52 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2.6 7.2.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.3-rc1 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/d41a9fcfb7f9ee36e4a4aaf5e7996bca6be1e7a9 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/b9cf42622b30178f554fa74411eec67e02d70411 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/892f34dc1819cceb8841005a68086710ce3763b6 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/dcaa0f1e86cbcb01f68131ae907b54cf299a3592 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/9af019e213ada5c3d0d33c515071a1414b6899f3 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/92e4979e1a770860b26aa3d90cce0c4c6a53833c | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/fb1194b78a163cc56bb9480c707fc34b53522359 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.