Vulnerability in Linux Kernel's Crypto Implementation Related to Sun4i Secure Sockets
CVE-2026-74438

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
15 August 2026

What is CVE-2026-74438?

A vulnerability has been identified in the Linux Kernel's cryptographic subsystem, specifically within the implementation for the sun4i secure sockets. The ineffective sun4i_ss_rng algorithm was marked for removal due to its insecure design and lack of practical usage. Key issues include a missing locking mechanism in sun4i_ss_prng_seed(), leading to a potential buffer overflow, and improper buffer handling in sun4i_ss_prng_generate(), which fails to adequately fill the destination buffer with cryptographically secure random bytes. As there is no known user of this code in practice, and given its theoretical usability only, removing this code segment has been deemed the most effective measure for enhancing overall security.

Affected Version(s)

Linux b8ae5c7387ad075ee61e8c8774ce2bca46bc9236 < 2eafecaba1b46bb9774eaf3556619fd5b6a17c1c

Linux b8ae5c7387ad075ee61e8c8774ce2bca46bc9236

Linux b8ae5c7387ad075ee61e8c8774ce2bca46bc9236 < 306ded31bfa00a69d25823a60d7c797170bfb4f8

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.