Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1325 CNY

100%

CVE-2026-46291— crypto: caam - guard HMAC key hex dumps in hash_digest_key

AI Predicted 5.3 Difficulty: Theoretical EPSS 0.17% · P6

Possible ATT&CK Techniques 1AI

T1081

Affected Version Matrix 18

VendorProductVersion RangeStatus
LinuxLinux045e36780f11523e26d1e4a8c78bdc57f4003bd0< e8e72fdf47bd5ef7abe642b034c6178a61a8580aaffected
045e36780f11523e26d1e4a8c78bdc57f4003bd0< cd849c07b8d706425e60a4dfcef54b7b67c967ceaffected
045e36780f11523e26d1e4a8c78bdc57f4003bd0< a9207798fe619cbc85c8744a9b9e2af1db2b6e1aaffected
045e36780f11523e26d1e4a8c78bdc57f4003bd0< 2adbfca7452eeac45117b8e803288a2767f7075faffected
045e36780f11523e26d1e4a8c78bdc57f4003bd0< c7e52fe3f7901ccb9cd29b3f7c683d809ba87e48affected
045e36780f11523e26d1e4a8c78bdc57f4003bd0< 5cffe3c136891aa4d579bf5c079a68f7cb371b0caffected
045e36780f11523e26d1e4a8c78bdc57f4003bd0< b8f12d9b00c1950779e5679b9c13908584682bb6affected
045e36780f11523e26d1e4a8c78bdc57f4003bd0< 177730a273b18e195263ed953853273e901b5064affected
… +10 more rows
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-46291

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
crypto: caam - guard HMAC key hex dumps in hash_digest_key
Source: NVD (National Vulnerability Database)
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: crypto: caam - guard HMAC key hex dumps in hash_digest_key Use print_hex_dump_devel() for dumping sensitive HMAC key bytes in hash_digest_key() to avoid leaking secrets at runtime when CONFIG_DYNAMIC_DEBUG is enabled.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linux kernel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux kernel是美国Linux基金会的开源操作系统Linux所使用的内核。 Linux kernel存在安全漏洞,该漏洞源于caam驱动中HMAC密钥十六进制转储,可能导致密钥泄露。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
LinuxLinux 045e36780f11523e26d1e4a8c78bdc57f4003bd0 ~ e8e72fdf47bd5ef7abe642b034c6178a61a8580a -
LinuxLinux 3.6 -

II. Public POCs for CVE-2026-46291

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-46291

登录查看更多情报信息。

Patches & Fixes for CVE-2026-46291 (8)

Same Patch Batch · Linux · 2026-06-08 · 41 CVEs total

CVE-2026-462899.8 CRITICALlib/scatterlist: fix length calculations in extract_kvec_to_sg
CVE-2026-462888.4 HIGHof: unittest: fix use-after-free in of_unittest_changeset()
CVE-2026-463078.3 HIGHwifi: ath5k: do not access array OOB
CVE-2026-463038.2 HIGHisofs: validate Rock Ridge CE continuation extent against volume size
CVE-2026-462747.8 HIGHio-wq: check that the predecessor is hashed in io_wq_remove_pending()
CVE-2026-463117.8 HIGHdrm/amdgpu/userq: fix access to stale wptr mapping
CVE-2026-462757.8 HIGHBluetooth: hci_uart: fix UAFs and race conditions in close and init paths
CVE-2026-462777.8 HIGHmm/zone_device: do not touch device folio after calling ->folio_free()
CVE-2026-462807.8 HIGHlib: test_hmm: evict device pages on file close to avoid use-after-free
CVE-2026-463067.5 HIGHflow_dissector: do not dissect PPPoE PFC frames
CVE-2026-463047.5 HIGHnvmet: avoid recursive nvmet-wq flush in nvmet_ctrl_free
CVE-2026-462997.0 HIGHhfsplus: fix held lock freed on hfsplus_fill_super()
CVE-2026-46287net: txgbe: fix RTNL assertion warning when remove module
CVE-2026-46286leds: qcom-lpg: Check for array overflow when selecting the high resolution
CVE-2026-46279mm/alloc_tag: clear codetag for pages allocated before page_ext initialization
CVE-2026-46285mtd: docg3: fix use-after-free in docg3_release()
CVE-2026-46284mm/hugetlb: fix early boot crash on parameters without '=' separator
CVE-2026-46283tpm: Use kfree_sensitive() to free auth session in tpm_dev_release()
CVE-2026-46282iio: frequency: admv1013: fix NULL pointer dereference on str
CVE-2026-46281vmalloc: fix buffer overflow in vrealloc_node_align()

Showing top 20 of 41 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-46291

No comments yet


Leave a comment