Executive brief
The Linux kernel's hardware random number generator (hwrng) core component has a flaw in its device registration logic. When a random number generator device fails to be set as the current RNG during registration, it is not properly removed from the kernel's internal list, creating a dangling reference. If the caller then frees the device memory after a failed registration, subsequent access to the list could cause a crash or memory corruption.
Technical details
The vulnerability is a use-after-free flaw in the hwrng_register() function in drivers/char/hw_random/core.c. The function adds an RNG device to the global rng_list before attempting to set it as the current_rng. If set_current_rng() fails and returns an error, the function returns without removing the device from rng_list, leaving a dangling pointer. If the caller then frees the RNG structure due to the failed registration, any subsequent code that iterates or accesses rng_list can trigger a use-after-free. The fix adds a list_del_init() call in the error path to properly clean up the list entry. The issue was introduced by commit 2bbb6983887f and affects all kernel versions with the hwrng registration path.
Affected products
- Linux Linux kernel 2.6.11 through 7.2 (all versions from commit 2bbb6983887f onward)
Timeline
- 2026-09-17: disclosed: CVE-2026-93163 published
- 2026-06-05: patched: Fix committed by Manos Pitsidianakis
- 2026-07-05: patched: Merged to stable tree by Herbert Xu