Junglewise Threat Intelligence

CVE-2026-92476: Linux kernel keembay AES initialization race condition

CVE-2026-92476 · Severity: info · CVSS 0 · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Keem Bay AES crypto driver had a timing bug where an interrupt handler could run before its supporting completion structure was initialized. An attacker with the ability to trigger IRQs on the device could cause a kernel crash or undefined behavior, affecting system stability and potentially enabling further exploitation.

Technical details

A race condition exists in kmb_ocs_aes_probe() where the device IRQ is registered before the irq_completion kernel structure is initialized. Once the IRQ handler (ocs_aes_irq_handler()) is registered, it can fire immediately and unconditionally calls complete() on the uninitialized completion object, leading to memory corruption or a kernel panic. The fix reorders initialization to call init_completion() before requesting the IRQ. The vulnerability is local to systems with Keem Bay OCS AES hardware and requires the ability to generate device interrupts.

Affected products

  • Linux Linux kernel All versions with keembay AES driver prior to patch commit fce20289dd622cc7ab78d72c8a979a9f8b7cb10e

Timeline

  • 2026-09-17: disclosed
  • 2026-09-14: patched: Stable kernel patches committed; upstream fix commit fce20289dd622cc7ab78d72c8a979a9f8b7cb10e

References

Related threats