Executive brief
A vulnerability was identified in the Loongson Random Number Generator (RNG) driver within the Linux kernel. This component, which is responsible for generating secure random numbers used in encryption, was found to have flaws that could lead to system instability or a compromise in the unpredictability of generated keys. Because the driver was both broken and unused by the core operating system, it has been completely removed to ensure system security.
Technical details
The loongson-rng driver (rng_alg) in the Linux kernel crypto subsystem contained a use-after-free vulnerability triggered by the incorrect use of wait_for_completion_interruptible(). Additionally, the driver failed to provide forward security, a critical requirement for cryptographic random number generators. The rng_alg framework for this hardware lacked in-kernel users and did not feed into the primary Linux entropy pool (hwrng). Due to these architectural flaws and the lack of active utilization, the driver was removed rather than patched. The fix is available in kernel versions 6.18.39, 7.1.4, and 7.2-rc1.
Affected products
- Linux Linux Kernel 6.18 to 6.18.39, 7.1 to 7.1.4
Timeline
- 2026-05-29: disclosed: Initial patch proposed to remove the driver
- 2026-07-18: patched: Patch committed to stable branches
- 2026-07-25: advisory: CVE published in NVD