{"id":"AZL-102192","summary":"CVE-2026-93160 affecting package kernel 6.6.150.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: atmel-ecc - reject hardware ECDH without a public key\n\nThe hardware ECDH path in atmel_ecdh_compute_shared_secret() uses the\nprivate key stored in the device. However, the public key is cached only\nafter atmel_ecdh_set_secret() successfully generated that private key\nfor the current tfm.\n\natmel_ecdh_generate_public_key() already rejects requests when no public\nkey is cached. Add the same check to atmel_ecdh_compute_shared_secret()\nto prevent the device from using a private key that was not generated\nfor the current tfm.","modified":"2026-09-21T05:34:22Z","published":"2026-09-17T17:18:11Z","upstream":["CVE-2026-93160"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93160"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.150.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-102192.json"}}],"schema_version":"1.9.0"}