PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-31391 Linux CVE debrief

A vulnerability in the Linux kernel's Atmel SHA204A crypto driver could allow a local attacker to cause a denial of service condition. The flaw exists in the driver's error handling path: when memory allocation fails during cryptographic operations, the driver fails to decrement the `tfm_count` reference counter. This leak causes the counter to remain elevated, eventually blocking legitimate read operations on the device. The vulnerability is local-access only with low attack complexity, requiring only low privileges and no user interaction. The issue has been resolved in stable kernel releases across multiple branches.

Vendor
Linux
Product
Unknown
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-14
Original CVE updated
2026-07-28
Advisory published
2026-07-14
Advisory updated
2026-07-28

Who should care

Organizations running Linux systems with Atmel SHA204A cryptographic hardware, particularly those providing multi-tenant or containerized environments where local user access is possible. Embedded systems and IoT deployments using this specific crypto accelerator should prioritize patching.

Technical summary

The atmel-sha204a driver in the Linux kernel contains a resource leak vulnerability. When memory allocation fails (OOM condition), the driver does not decrement the `tfm_count` counter before returning an error. This counter tracks active transform contexts; failure to decrement on error paths causes the count to remain artificially elevated. Once `tfm_count` reaches its maximum, subsequent legitimate read operations on the SHA204A device are blocked, resulting in a denial of service. The vulnerability affects kernel versions from 5.3 through multiple stable branches up to 7.0-rc2. Patches have been backported to all maintained stable branches.

Defensive priority

medium

Recommended defensive actions

  • Apply kernel updates to patched versions: 5.10.253+, 6.1.167+, 6.6.130+, 6.12.78+, 6.18.20+, 6.19.10+, or 7.0-rc3+
  • If running affected kernel versions with Atmel SHA204A hardware, prioritize patching systems where local untrusted access is possible
  • Monitor for kernel OOM conditions that could trigger the vulnerable code path
  • Review system logs for SHA204A driver errors as potential indicators of exploitation attempts

Evidence notes

Vulnerability description and patch references sourced from NVD. Affected version ranges derived from CPE criteria in source metadata. CVSS 3.1 vector confirms local attack vector with availability impact. Multiple stable kernel patches available via kernel.org git references.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-31391 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-31391

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-31391 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-31391

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/1ab70c260cf16f931a728b2cb63fff5f38c814d8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/2bfc83cee05f8b9604502df27d94e8e2b4a3dbf1

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/66ee9c1c3575b5d6afc340faca00fd40ed5b7ad9

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6f502049a96b368ea6646c49d9520d6f69a101fa

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c2d0c45dbb9eb272385ae919b17eef5a5318d3f8

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d240b079a37e90af03fd7dfec94930eb6c83936e

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/fd262dc6d758232511127372eba866b7600739ba

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.