CVE-2026-93160EPSS p6.6%
CVE-2026-93160CVE-2026-93160
Description
In the Linux kernel, the following vulnerability has been resolved:
crypto: atmel-ecc - reject hardware ECDH without a public key
The hardware ECDH path in atmel_ecdh_compute_shared_secret() uses the
private key stored in the device. However, the public key is cached only
after atmel_ecdh_set_secret() successfully generated that private key
for the current tfm.
atmel_ecdh_generate_public_key() already rejects requests when no public
key is cached. Add the same check to atmel_ecdh_compute_shared_secret()
to prevent the device from using a private key that was not generated
for the current tfm.
Scoring
| EPSS | 0.18% probability of exploitation · percentile 6.6% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-17 |