hwrng: core - fix rng list on registration error

Summary

CVECVE-2026-93163
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-09-17 17:18:11 UTC
Updated2026-09-17 17:18:11 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: hwrng: core - fix rng list on registration error hwrng_register(rng) does the following: 1. Checks if rng has name and read methods set 2. Checks if the name already exists 3. Adds rng to global rng_list 4. May try to set rng to current_rng If step 4 fails, it returns an error. However, it does not remove the rng from rng_list, causing a dangling reference which can result in use-after-free if the caller frees rng, since registration failed. Add a list_del_init() cleanup step.

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected 2bbb6983887fefc8026beab01198d30f47b7bd22 de4f1bcb61a73cc896decdbd27d61a34add93b53 git Not specified
CNA Linux Linux affected 2bbb6983887fefc8026beab01198d30f47b7bd22 cf293c9c7424de0d04b51367d07f40570ce80231 git Not specified
CNA Linux Linux affected 2bbb6983887fefc8026beab01198d30f47b7bd22 bee8d1fcdc8f389b595b0a4cf6fe8440f499458a git Not specified
CNA Linux Linux affected 2bbb6983887fefc8026beab01198d30f47b7bd22 3a5834db2b1ce25649f330e78efe1ccde78967fd git Not specified
CNA Linux Linux affected 42802952a2725f85f7e36ee3b29593af5fe87197 git Not specified
CNA Linux Linux affected 4.9.320 4.10 semver Not specified
CNA Linux Linux affected 4.14 Not specified
CNA Linux Linux unaffected 4.14 semver Not specified
CNA Linux Linux unaffected 6.12.110 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.52 6.18.* semver Not specified
CNA Linux Linux unaffected 7.2.6 7.2.* semver Not specified
CNA Linux Linux unaffected 7.3-rc1 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/3a5834db2b1ce25649f330e78efe1ccde78967fd 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/bee8d1fcdc8f389b595b0a4cf6fe8440f499458a 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/cf293c9c7424de0d04b51367d07f40570ce80231 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/de4f1bcb61a73cc896decdbd27d61a34add93b53 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report