Vulnerability in Linux Kernel's sun8i-ss Support Affects Security Operations
CVE-2026-80833
Currently unrated
What is CVE-2026-80833?
The vulnerability within the Linux kernel relates to the phased removal of the unused crypto_rng interface for hardware PRNGs, specifically impacting the sun8i-ss support. The driver exhibited critical weaknesses, including a use-after-free flaw arising from improper handling during DMA operation shutdown, and a buffer overread issue potentially leading to data leakage. Given its obsolescence, the decision was made to remove the driver entirely, consolidating security efforts while eliminating unnecessary risks from the codebase.
Affected Version(s)
Linux ac2614d721dea2ff273af19c6c5d508d58a2bb3e < 8ab58786b4c63b8f1b6c522f33bb67a3c8c2791f
Linux ac2614d721dea2ff273af19c6c5d508d58a2bb3e
Linux 5.10