Answer in brief
CVE-2026-93160 records a Unknown severity vulnerability in crypto: atmel-ecc - reject hardware ECDH without a public key. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=11105693fa05f499532b330da65c78ff93ed4440 <5e33791dfcc6459e402a524669093cd953d5b2df || >=11105693fa05f499532b330da65c78ff93ed4440 <33241f198287960bba5fc2251400896762650bfa || >=11105693fa05f499532b330da65c78ff93ed4440 <3ea8b780d68f02fe235c5051ce8ac4b4940b9259 || >=11105693fa05f499532b330da65c78ff93ed4440 <6457162f74f45284ade2da644a4f0c54758ac0a6 || >=11105693fa05f499532b330da65c78ff93ed4440 <2b40bab362d2b598f34e5ccd4694cedc3c2553d4 || >=11105693fa05f499532b330da65c78ff93ed4440 <e64d6f1aae8c837cb3f0446bf44108226d7370f4 || >=11105693fa05f499532b330da65c78ff93ed4440 <add28e9988902d29ea93f4869280b4a16a049ea5 || >=11105693fa05f499532b330da65c78ff93ed4440 <f240f9b588f4e2de89822adebf560a96b5d263ed | 5e33791dfcc6459e402a524669093cd953d5b2df, 33241f198287960bba5fc2251400896762650bfa, 3ea8b780d68f02fe235c5051ce8ac4b4940b9259, 6457162f74f45284ade2da644a4f0c54758ac0a6, 2b40bab362d2b598f34e5ccd4694cedc3c2553d4, e64d6f1aae8c837cb3f0446bf44108226d7370f4, add28e9988902d29ea93f4869280b4a16a049ea5, f240f9b588f4e2de89822adebf560a96b5d263ed |
| Linux/Linuxgeneric | 4.14 | Not reported |
Published upstream
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 17, 2026
In the Linux kernel, the following vulnerability has been resolved: crypto: atmel-ecc - reject hardware ECDH without a public key The hardware ECDH path in atmel_ecdh_compute_shared_secret() uses the private key stored in the device. However, the public key is cached only after atmel_ecdh_set_secret() successfully generated that private key for the current tfm. atmel_ecdh_generate_public_key() already rejects requests when no public key is cached. Add the same check to atmel_ecdh_compute_shared_secret() to prevent the device from using a private key that was not generated for the current tfm.
Quoted source text, attributed separately from HOL analysis.