Linux Kernel Vulnerability Affecting Sun8i-ce Crypto RNG Interface
CVE-2026-80834
What is CVE-2026-80834?
A vulnerability in the Linux kernel's sun8i-ce crypto RNG interface has been identified and resolved. This interface, used for hardware pseudo-random number generation (PRNG), was deemed redundant due to the existing hwrng and the primary Linux RNG. The sun8i-ce driver had a notable use-after-free flaw in its generate() function stemming from improper handling of DMA shutdown during signals. While resolving the issue, the decision was made to remove the cryptographically obsolete interface entirely due to its lack of use and the broader context of removal of most relevant drivers.
Affected Version(s)
Linux 5eb7e946888493959b1c393144934afcbcd0cfc1 < 1017f987c5f0841f00408a78f947990c9d84b346
Linux 5eb7e946888493959b1c393144934afcbcd0cfc1 < 011556f71d094da61379ae3672692cae2795304e
Linux 5.10