CVE-2026-93161

high

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - clear AES key schedule from stack qat_alg_xts_reverse_key() expands the forward XTS AES key on the stack. That schedule contains key material and can remain in the stack frame. Clear the temporary crypto_aes_ctx with memzero_explicit() after the copy.

References

https://git.kernel.org/stable/c/fb1194b78a163cc56bb9480c707fc34b53522359

https://git.kernel.org/stable/c/dcaa0f1e86cbcb01f68131ae907b54cf299a3592

https://git.kernel.org/stable/c/d41a9fcfb7f9ee36e4a4aaf5e7996bca6be1e7a9

https://git.kernel.org/stable/c/b9cf42622b30178f554fa74411eec67e02d70411

https://git.kernel.org/stable/c/9af019e213ada5c3d0d33c515071a1414b6899f3

https://git.kernel.org/stable/c/92e4979e1a770860b26aa3d90cce0c4c6a53833c

https://git.kernel.org/stable/c/892f34dc1819cceb8841005a68086710ce3763b6

Details

Source: Mitre, NVD

Published: 2026-09-17

Updated: 2026-09-17

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 7.1

Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

Severity: High

EPSS

EPSS: 0.00206