Linux Kernel Vulnerability in Qcom-rng Random Number Generation
CVE-2026-80922
Currently unrated
What is CVE-2026-80922?
A vulnerability exists within the Linux kernel's Qcom-rng module that improperly handles zero as a valid random number. This flaw can lead to outputs that are distinguishable from true random, undermining the integrity and security of cryptographic operations. Properly allowing zero enhances the randomness of generated numbers, making them indistinguishable from an ideal random sequence.
Affected Version(s)
Linux f29cd5bb64c258f29b4c49452532481f50eb43ca < 813e6718a199befc4f26f54bdd899fbfa11515e5
Linux f29cd5bb64c258f29b4c49452532481f50eb43ca < 4c0018320942003bfedd0a1c4cce3f036d363a7f
Linux f29cd5bb64c258f29b4c49452532481f50eb43ca < 143c74034a1c47b0a1a64e7ca7153e7739bd1244