CVE-2026-93160
crypto: atmel-ecc - reject hardware ECDH without a public key
mediumEPSS 0.2%
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: atmel-ecc - reject hardware ECDH without a public key The hardware ECDH path in atmel_ecdh_compute_shared_secret() uses the private key stored in the device. However, the public key is cached only after atmel_ecdh_set_secret() successfully generated that private key for the current tfm. atmel_ecdh_generate_public_key() already rejects requests when no public key is cached. Add the same check to atmel_ecdh_compute_shared_secret() to prevent the device from using a private key that was not generated for the current tfm.
Affected operating systems
linux
debian / linuxtrixie
Metrics
Show all metrics
Severity
medium
57.85
no public PoC known
5.5
Published
2026-09-19 01:05 UTC
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- New CVE Received2026-09-17 17:18 UTC· 416baaa9-dc9f-4396-8d5f-8c081fb06d67
- Description: In the Linux kernel, the following vulnerability has been resolved: crypto: atmel-ecc - reject hardware ECDH without a public key The hardware ECDH path in atmel_ecdh_compute_shared_secret() uses the private key stored in the device. However, the public key is cached only after atmel_ecdh_set_secret() successfully generated that private key for the current tfm. atmel_ecdh_generate_public_key() already rejects requests when no public key is cached. Add the same check to atmel_ecdh_compute_shared_secret() to prevent the device from using a private key that was not generated for the current tfm.
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/93xxx/CVE-2026-93160.json">CVE-2026-93160</a>
- Reference: https://git.kernel.org/stable/c/2b40bab362d2b598f34e5ccd4694cedc3c2553d4
- Reference: https://git.kernel.org/stable/c/33241f198287960bba5fc2251400896762650bfa