CVE-2026-93161EPSS p10.8%
CVE-2026-93161CVE-2026-93161
Description
In the Linux kernel, the following vulnerability has been resolved:
crypto: qat - clear AES key schedule from stack
qat_alg_xts_reverse_key() expands the forward XTS AES key on the stack.
That schedule contains key material and can remain in the stack frame.
Clear the temporary crypto_aes_ctx with memzero_explicit() after the copy.
Scoring
| EPSS | 0.21% probability of exploitation · percentile 10.8% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-17 |