All of lore.kernel.org
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-72151: tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt
Date: Sat, 15 Aug 2026 15:03:50 +0900	[thread overview]
Message-ID: <2026081534-CVE-2026-72151-db64@gregkh> (raw)

From: Greg Kroah-Hartman <gregkh@kernel.org>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt

tpm_buf_append_salt() in drivers/char/tpm/tpm2-sessions.c calls
crypto_kpp_generate_public_key() and crypto_kpp_compute_shared_secret()
without installing a completion callback, discards both return values,
and immediately frees the kpp_request via kpp_request_free(). When the
resolved ecdh-nist-p256 KPP backend is asynchronous (atmel-ecc, HPRE,
keembay-ocs), either operation returns -EINPROGRESS and the deferred
completion worker dereferences the freed request.

The path fires automatically from the hwrng_fillfn kernel thread via
tpm_get_random -> tpm2_get_random -> tpm2_start_auth_session ->
tpm_buf_append_salt on every entropy poll, without any userland action.

Install crypto_req_done as the completion callback, wrap both KPP
operations in crypto_wait_req(), and propagate errors to the caller.
The wait is a no-op for synchronous backends.

The Linux kernel CVE team has assigned CVE-2026-72151 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 6.10 with commit 1085b8276bb4239daa7008f0dcd5c973e4bd690f and fixed in 6.12.97 with commit 111e520efbe82b324bc42b1999b723c0619eea6d
	Issue introduced in 6.10 with commit 1085b8276bb4239daa7008f0dcd5c973e4bd690f and fixed in 6.18.40 with commit 934d1cd40e2893bf7a041b54f6afd1c008d7a21c
	Issue introduced in 6.10 with commit 1085b8276bb4239daa7008f0dcd5c973e4bd690f and fixed in 7.1.5 with commit 493333f167926c7adab8e7563e21ad71d8af84fa
	Issue introduced in 6.10 with commit 1085b8276bb4239daa7008f0dcd5c973e4bd690f and fixed in 7.2-rc1 with commit 73851a7c43dfa52d2ed9415889b33daf85da0ed9

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-72151
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/char/tpm/tpm2-sessions.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/111e520efbe82b324bc42b1999b723c0619eea6d
	https://git.kernel.org/stable/c/934d1cd40e2893bf7a041b54f6afd1c008d7a21c
	https://git.kernel.org/stable/c/493333f167926c7adab8e7563e21ad71d8af84fa
	https://git.kernel.org/stable/c/73851a7c43dfa52d2ed9415889b33daf85da0ed9

                 reply	other threads:[~2026-08-15  6:13 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2026081534-CVE-2026-72151-db64@gregkh \
    --to=gregkh@linuxfoundation.org \
    --cc=cve@kernel.org \
    --cc=gregkh@kernel.org \
    --cc=linux-cve-announce@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.