Entropy Integrity Issue in Linux Kernel Due to Atmel SHA204A Buffer Management
CVE-2026-74402
What is CVE-2026-74402?
A vulnerability in the Linux kernel related to the Atmel SHA204A device has been identified, where both blocking and non-blocking random number generation logic failed to produce valid entropy due to improper buffer management. This flaw led to a situation where reading from the buffer, beginning at byte 1, only retrieved minimal random data, which undermined the cryptographic integrity of systems leveraging this hardware. The issue was resolved through enhanced buffer management, ensuring that random data can be accurately fetched and utilized.
Affected Version(s)
Linux da001fb651b00e1deeaf24767dd691ae8152a4f5 < 76269a91fd9560c5f03c3e59421a0329e39a6661
Linux da001fb651b00e1deeaf24767dd691ae8152a4f5 < 9039bb4f238474379221fc933c34f19f0cba501b
Linux da001fb651b00e1deeaf24767dd691ae8152a4f5