{"api_version":"1","generated_at":"2026-09-17T23:58:42+00:00","cve":"CVE-2026-93156","urls":{"html":"https://cve.report/CVE-2026-93156","api":"https://cve.report/api/cve/CVE-2026-93156.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-93156","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-93156"},"summary":{"title":"crypto: rk3288 - fail ahash requests on HASH idle timeout","description":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: rk3288 - fail ahash requests on HASH idle timeout\n\nrk_hash_run() waits for RK_CRYPTO_HASH_STS to become idle after the\nfinal DMA transfer, but ignores the poll result. If the hash engine\nnever becomes idle, the driver still reads the digest registers and\nfinalizes the request with the previous success value.\n\nStore the poll result and finalize the request with the timeout error\nbefore reading the digest registers.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-09-17 17:18:10","updated_at":"2026-09-17 17:18:10"},"problem_types":[],"metrics":[],"references":[{"url":"https://git.kernel.org/stable/c/a22dc48d58ef46e21c0172ba83c33f1c9859e63c","name":"https://git.kernel.org/stable/c/a22dc48d58ef46e21c0172ba83c33f1c9859e63c","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/e7d8ddd471d2895f1d4098832c21121d4191adaa","name":"https://git.kernel.org/stable/c/e7d8ddd471d2895f1d4098832c21121d4191adaa","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/2feb52b2796c25510903bf0f18a84cde44631391","name":"https://git.kernel.org/stable/c/2feb52b2796c25510903bf0f18a84cde44631391","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/0a261177ad3245af393548d0632226d99c643191","name":"https://git.kernel.org/stable/c/0a261177ad3245af393548d0632226d99c643191","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/ae150db7826f21e8d19e54fb6243169628809c4d","name":"https://git.kernel.org/stable/c/ae150db7826f21e8d19e54fb6243169628809c4d","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-93156","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93156","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 37bc22159c456ad43fb852fc6ed60f4081df25df a22dc48d58ef46e21c0172ba83c33f1c9859e63c git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 37bc22159c456ad43fb852fc6ed60f4081df25df 2feb52b2796c25510903bf0f18a84cde44631391 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 37bc22159c456ad43fb852fc6ed60f4081df25df e7d8ddd471d2895f1d4098832c21121d4191adaa git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 37bc22159c456ad43fb852fc6ed60f4081df25df 0a261177ad3245af393548d0632226d99c643191 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 37bc22159c456ad43fb852fc6ed60f4081df25df ae150db7826f21e8d19e54fb6243169628809c4d git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 6.2","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.2 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.157 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.110 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.52 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2.6 7.2.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.3-rc1 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/crypto/rockchip/rk3288_crypto_ahash.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"a22dc48d58ef46e21c0172ba83c33f1c9859e63c","status":"affected","version":"37bc22159c456ad43fb852fc6ed60f4081df25df","versionType":"git"},{"lessThan":"2feb52b2796c25510903bf0f18a84cde44631391","status":"affected","version":"37bc22159c456ad43fb852fc6ed60f4081df25df","versionType":"git"},{"lessThan":"e7d8ddd471d2895f1d4098832c21121d4191adaa","status":"affected","version":"37bc22159c456ad43fb852fc6ed60f4081df25df","versionType":"git"},{"lessThan":"0a261177ad3245af393548d0632226d99c643191","status":"affected","version":"37bc22159c456ad43fb852fc6ed60f4081df25df","versionType":"git"},{"lessThan":"ae150db7826f21e8d19e54fb6243169628809c4d","status":"affected","version":"37bc22159c456ad43fb852fc6ed60f4081df25df","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/crypto/rockchip/rk3288_crypto_ahash.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"6.2"},{"lessThan":"6.2","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.157","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.110","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.52","versionType":"semver"},{"lessThanOrEqual":"7.2.*","status":"unaffected","version":"7.2.6","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.3-rc1","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.157","versionStartIncluding":"6.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.110","versionStartIncluding":"6.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.52","versionStartIncluding":"6.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2.6","versionStartIncluding":"6.2","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.3-rc1","versionStartIncluding":"6.2","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: rk3288 - fail ahash requests on HASH idle timeout\n\nrk_hash_run() waits for RK_CRYPTO_HASH_STS to become idle after the\nfinal DMA transfer, but ignores the poll result. If the hash engine\nnever becomes idle, the driver still reads the digest registers and\nfinalizes the request with the previous success value.\n\nStore the poll result and finalize the request with the timeout error\nbefore reading the digest registers."}],"providerMetadata":{"dateUpdated":"2026-09-17T16:11:51.461Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/a22dc48d58ef46e21c0172ba83c33f1c9859e63c"},{"url":"https://git.kernel.org/stable/c/2feb52b2796c25510903bf0f18a84cde44631391"},{"url":"https://git.kernel.org/stable/c/e7d8ddd471d2895f1d4098832c21121d4191adaa"},{"url":"https://git.kernel.org/stable/c/0a261177ad3245af393548d0632226d99c643191"},{"url":"https://git.kernel.org/stable/c/ae150db7826f21e8d19e54fb6243169628809c4d"}],"title":"crypto: rk3288 - fail ahash requests on HASH idle timeout","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-93156","datePublished":"2026-09-17T16:11:51.461Z","dateReserved":"2026-09-17T16:02:15.089Z","dateUpdated":"2026-09-17T16:11:51.461Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-17 17:18:10","lastModifiedDate":"2026-09-17 17:18:10","problem_types":[],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"93156","Ordinal":"1","Title":"crypto: rk3288 - fail ahash requests on HASH idle timeout","CVE":"CVE-2026-93156","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"93156","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: rk3288 - fail ahash requests on HASH idle timeout\n\nrk_hash_run() waits for RK_CRYPTO_HASH_STS to become idle after the\nfinal DMA transfer, but ignores the poll result. If the hash engine\nnever becomes idle, the driver still reads the digest registers and\nfinalizes the request with the previous success value.\n\nStore the poll result and finalize the request with the timeout error\nbefore reading the digest registers.","Type":"Description","Title":"crypto: rk3288 - fail ahash requests on HASH idle timeout"}]}}}