PatchSiren cyber security CVE debrief
CVE-2026-31391 Linux CVE debrief
A vulnerability in the Linux kernel's Atmel SHA204A crypto driver could allow a local attacker to cause a denial of service condition. The flaw exists in the driver's error handling path: when memory allocation fails during cryptographic operations, the driver fails to decrement the `tfm_count` reference counter. This leak causes the counter to remain elevated, eventually blocking legitimate read operations on the device. The vulnerability is local-access only with low attack complexity, requiring only low privileges and no user interaction. The issue has been resolved in stable kernel releases across multiple branches.
- Vendor
- Linux
- Product
- Unknown
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-14
- Original CVE updated
- 2026-07-28
- Advisory published
- 2026-07-14
- Advisory updated
- 2026-07-28
Who should care
Organizations running Linux systems with Atmel SHA204A cryptographic hardware, particularly those providing multi-tenant or containerized environments where local user access is possible. Embedded systems and IoT deployments using this specific crypto accelerator should prioritize patching.
Technical summary
The atmel-sha204a driver in the Linux kernel contains a resource leak vulnerability. When memory allocation fails (OOM condition), the driver does not decrement the `tfm_count` counter before returning an error. This counter tracks active transform contexts; failure to decrement on error paths causes the count to remain artificially elevated. Once `tfm_count` reaches its maximum, subsequent legitimate read operations on the SHA204A device are blocked, resulting in a denial of service. The vulnerability affects kernel versions from 5.3 through multiple stable branches up to 7.0-rc2. Patches have been backported to all maintained stable branches.
Defensive priority
medium
Recommended defensive actions
- Apply kernel updates to patched versions: 5.10.253+, 6.1.167+, 6.6.130+, 6.12.78+, 6.18.20+, 6.19.10+, or 7.0-rc3+
- If running affected kernel versions with Atmel SHA204A hardware, prioritize patching systems where local untrusted access is possible
- Monitor for kernel OOM conditions that could trigger the vulnerable code path
- Review system logs for SHA204A driver errors as potential indicators of exploitation attempts
Evidence notes
Vulnerability description and patch references sourced from NVD. Affected version ranges derived from CPE criteria in source metadata. CVSS 3.1 vector confirms local attack vector with availability impact. Multiple stable kernel patches available via kernel.org git references.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-31391 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-31391
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-31391 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-31391
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/1ab70c260cf16f931a728b2cb63fff5f38c814d8
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/2bfc83cee05f8b9604502df27d94e8e2b4a3dbf1
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/66ee9c1c3575b5d6afc340faca00fd40ed5b7ad9
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/6f502049a96b368ea6646c49d9520d6f69a101fa
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/c2d0c45dbb9eb272385ae919b17eef5a5318d3f8
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/d240b079a37e90af03fd7dfec94930eb6c83936e
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://git.kernel.org/stable/c/fd262dc6d758232511127372eba866b7600739ba
416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.