CVE-2026-93161

Source
https://cve.org/CVERecord?id=CVE-2026-93161
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93161.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-93161
Downstream
Published
2026-09-17T16:11:55Z
Modified
2026-09-18T03:48:44Z
Summary
crypto: qat - clear AES key schedule from stack
Details

In the Linux kernel, the following vulnerability has been resolved:

crypto: qat - clear AES key schedule from stack

qat_alg_xts_reverse_key() expands the forward XTS AES key on the stack. That schedule contains key material and can remain in the stack frame.

Clear the temporary crypto_aes_ctx with memzero_explicit() after the copy.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/93xxx/CVE-2026-93161.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5106dfeaeabea73d5132daab1d89d57b57fa98b7
Fixed
b9cf42622b30178f554fa74411eec67e02d70411
Fixed
fb1194b78a163cc56bb9480c707fc34b53522359
Fixed
892f34dc1819cceb8841005a68086710ce3763b6
Fixed
dcaa0f1e86cbcb01f68131ae907b54cf299a3592
Fixed
9af019e213ada5c3d0d33c515071a1414b6899f3
Fixed
92e4979e1a770860b26aa3d90cce0c4c6a53833c
Fixed
d41a9fcfb7f9ee36e4a4aaf5e7996bca6be1e7a9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93161.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.221
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.188
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.157
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.110
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.52
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-93161.json"