Linux Kernel Vulnerability in Qcom-rng Random Number Generation
CVE-2026-80922

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-80922?

A vulnerability exists within the Linux kernel's Qcom-rng module that improperly handles zero as a valid random number. This flaw can lead to outputs that are distinguishable from true random, undermining the integrity and security of cryptographic operations. Properly allowing zero enhances the randomness of generated numbers, making them indistinguishable from an ideal random sequence.

Affected Version(s)

Linux f29cd5bb64c258f29b4c49452532481f50eb43ca < 813e6718a199befc4f26f54bdd899fbfa11515e5

Linux f29cd5bb64c258f29b4c49452532481f50eb43ca < 4c0018320942003bfedd0a1c4cce3f036d363a7f

Linux f29cd5bb64c258f29b4c49452532481f50eb43ca < 143c74034a1c47b0a1a64e7ca7153e7739bd1244

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.