Junglewise Threat Intelligence

CVE-2026-93159: Linux kernel atmel-sha204a heap info leak on I2C transfer failure

CVE-2026-93159 · Severity: info · Published 2026-09-17

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's Atmel SHA204A random number generator (RNG) driver contains a flaw in error handling during I2C communication. When an I2C transaction fails, the driver previously left allocated memory structures in place, allowing sensitive heap data to be misinterpreted as valid random data in subsequent operations. This could leak kernel memory contents to applications requesting random numbers.

Technical details

The vulnerability is an information disclosure (heap leak) in the atmel-sha204a crypto driver's nonblocking RNG path. When an asynchronous I2C request fails, the completion callback receives a non-zero status but previously only logged a warning without freeing the allocated work_data structure or clearing the rng->priv pointer. This left stale state in memory that subsequent read attempts could observe and incorrectly interpret as valid RNG completion data, leaking kernel heap contents. The fix adds a kfree() call and early return in the failure path to properly clean up allocated resources. The vulnerability is local to systems with the affected driver; no network attack vector exists.

Affected products

  • Linux Linux kernel Versions with atmel-sha204a driver support (approximately 4.x through 6.x before the patch)

Timeline

  • 2026-09-17: disclosed
  • 2026-06-13: patched: Upstream fix committed
  • 2026-09-14: advisory: Backport to stable kernels

References

Related threats