CVE-2026-46075EPSS p3.0%
CVE-2026-46075CVE-2026-46075
linux / linux_kernel
Description
In the Linux kernel, the following vulnerability has been resolved:
crypto: atmel-sha204a - Fix potential UAF and memory leak in remove path
Unregister the hwrng to prevent new ->read() calls and flush the Atmel
I2C workqueue before teardown to prevent a potential UAF if a queued
callback runs while the device is being removed.
Drop the early return to ensure sysfs entries are removed and
->hwrng.priv is freed, preventing a memory leak.
Scoring
| CVSS | 7.8 () |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.13% probability of exploitation · percentile 3.0% · 2026-08-03T12:00:16Z |
| Last modified | 2026-06-24 |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.