{"id":"CVE-2026-93161","title":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - clear AES key schedule from stack\n\nqat_alg_xts_reverse_key() expands the forward XTS AES key on the stack.\nThat schedule contains key material and can rem…","summary":"In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - clear AES key schedule from stack\n\nqat_alg_xts_reverse_key() expands the forward XTS AES key on the stack.\nThat schedule contains key material and can rem…","severity":"none","vendor":"Linux","product":"Linux","affected":["Linux >= 5106dfeaeabea73d5132daab1d89d57b57fa98b7 < b9cf42622b30178f554fa74411eec67e02d70411","Linux >= 5106dfeaeabea73d5132daab1d89d57b57fa98b7 < fb1194b78a163cc56bb9480c707fc34b53522359","Linux >= 5106dfeaeabea73d5132daab1d89d57b57fa98b7 < 892f34dc1819cceb8841005a68086710ce3763b6","Linux >= 5106dfeaeabea73d5132daab1d89d57b57fa98b7 < dcaa0f1e86cbcb01f68131ae907b54cf299a3592","Linux >= 5106dfeaeabea73d5132daab1d89d57b57fa98b7 < 9af019e213ada5c3d0d33c515071a1414b6899f3","Linux >= 5106dfeaeabea73d5132daab1d89d57b57fa98b7 < 92e4979e1a770860b26aa3d90cce0c4c6a53833c","Linux >= 5106dfeaeabea73d5132daab1d89d57b57fa98b7 < d41a9fcfb7f9ee36e4a4aaf5e7996bca6be1e7a9","Linux 5.11"],"published":"2026-09-17","updated":"2026-09-17","sourceUpdated":"2026-09-17T17:18:11.533","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-93161","references":[{"url":"https://git.kernel.org/stable/c/892f34dc1819cceb8841005a68086710ce3763b6","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/92e4979e1a770860b26aa3d90cce0c4c6a53833c","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/9af019e213ada5c3d0d33c515071a1414b6899f3","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/b9cf42622b30178f554fa74411eec67e02d70411","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/d41a9fcfb7f9ee36e4a4aaf5e7996bca6be1e7a9","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/dcaa0f1e86cbcb01f68131ae907b54cf299a3592","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"},{"url":"https://git.kernel.org/stable/c/fb1194b78a163cc56bb9480c707fc34b53522359","label":"416baaa9-dc9f-4396-8d5f-8c081fb06d67"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-17T16:21:47.739Z","epss":0.00206,"epssPercentile":0.10936,"slug":"CVE-2026-93161","body":"## Overview\n\nIn the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: qat - clear AES key schedule from stack\n\nqat_alg_xts_reverse_key() expands the forward XTS AES key on the stack.\nThat schedule contains key material and can remain in the stack frame.\n\nClear the temporary crypto_aes_ctx with memzero_explicit() after the copy.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}