Vulnerability Bulletins

CVE-2026-46075

   
Affected software LINUX KERNEL
 
In the Linux kernel, the following vulnerability has been resolved:

crypto: atmel-sha204a - Fix potential UAF and memory leak in remove path

Unregister the hwrng to prevent new ->read() calls and flush the Atmel
I2C workqueue before teardown to prevent a potential UAF if a queued
callback runs while the device is being removed.

Drop the early return to ensure sysfs entries are removed and
->hwrng.priv is freed, preventing a memory leak.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-46075