CVE-2026-93160

Source
https://cve.org/CVERecord?id=CVE-2026-93160
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93160.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93160
Downstream
Published
2026-09-17T16:11:54Z
Modified
2026-09-19T03:47:22Z
Summary
crypto: atmel-ecc - reject hardware ECDH without a public key
Details

In the Linux kernel, the following vulnerability has been resolved:

crypto: atmel-ecc - reject hardware ECDH without a public key

The hardware ECDH path in atmel_ecdh_compute_shared_secret() uses the private key stored in the device. However, the public key is cached only after atmel_ecdh_set_secret() successfully generated that private key for the current tfm.

atmel_ecdh_generate_public_key() already rejects requests when no public key is cached. Add the same check to atmel_ecdh_compute_shared_secret() to prevent the device from using a private key that was not generated for the current tfm.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93160.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
11105693fa05f499532b330da65c78ff93ed4440
Fixed
5e33791dfcc6459e402a524669093cd953d5b2df
Fixed
33241f198287960bba5fc2251400896762650bfa
Fixed
3ea8b780d68f02fe235c5051ce8ac4b4940b9259
Fixed
6457162f74f45284ade2da644a4f0c54758ac0a6
Fixed
2b40bab362d2b598f34e5ccd4694cedc3c2553d4
Fixed
e64d6f1aae8c837cb3f0446bf44108226d7370f4
Fixed
add28e9988902d29ea93f4869280b4a16a049ea5
Fixed
f240f9b588f4e2de89822adebf560a96b5d263ed

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93160.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.14.0
Fixed
5.10.270
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93160.json"