CVE-2026-93161
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: qat - clear AES key schedule from stack qat_alg_xts_reverse_key() expands the forward XTS AES key on the stack. That schedule contains key material and can remain in the stack frame. Clear the temporary crypto_aes_ctx with memzero_explicit() after the copy.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://git.kernel.org/stable/c/892f34dc1819cceb8841005a68086710ce3763b6
- https://git.kernel.org/stable/c/92e4979e1a770860b26aa3d90cce0c4c6a53833c
- https://git.kernel.org/stable/c/9af019e213ada5c3d0d33c515071a1414b6899f3
- https://git.kernel.org/stable/c/b9cf42622b30178f554fa74411eec67e02d70411
- https://git.kernel.org/stable/c/d41a9fcfb7f9ee36e4a4aaf5e7996bca6be1e7a9
- https://git.kernel.org/stable/c/dcaa0f1e86cbcb01f68131ae907b54cf299a3592
- https://git.kernel.org/stable/c/fb1194b78a163cc56bb9480c707fc34b53522359
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.