---
id: CVE-2026-80922
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  crypto: qcom-rng - Allow zero as a random number

  Zero is a valid random number and needs to be allowed
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  crypto: qcom-rng - Allow zero as a random number

  Zero is a valid random number and needs to be allowed.  Otherwise the
  output is distinguishable from random.
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= f29cd5bb64c258f29b4c49452532481f50eb43ca <
    813e6718a199befc4f26f54bdd899fbfa11515e5
  - >-
    Linux >= f29cd5bb64c258f29b4c49452532481f50eb43ca <
    4c0018320942003bfedd0a1c4cce3f036d363a7f
  - >-
    Linux >= f29cd5bb64c258f29b4c49452532481f50eb43ca <
    143c74034a1c47b0a1a64e7ca7153e7739bd1244
  - >-
    Linux >= f29cd5bb64c258f29b4c49452532481f50eb43ca <
    3c7101cfc52e378bcb0a46962145e39c9051dd5d
  - >-
    Linux >= f29cd5bb64c258f29b4c49452532481f50eb43ca <
    4ef04bdc0c9f98836d1638be516f6bf1bad55f69
  - Linux 6.7
published: '2026-09-09'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T17:17:47.383'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80922'
references:
  - url: 'https://git.kernel.org/stable/c/143c74034a1c47b0a1a64e7ca7153e7739bd1244'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/3c7101cfc52e378bcb0a46962145e39c9051dd5d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4c0018320942003bfedd0a1c4cce3f036d363a7f'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/4ef04bdc0c9f98836d1638be516f6bf1bad55f69'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/813e6718a199befc4f26f54bdd899fbfa11515e5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-09T17:16:03.090Z'
epss: 0.00156
epssPercentile: 0.05219
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

crypto: qcom-rng - Allow zero as a random number

Zero is a valid random number and needs to be allowed.  Otherwise the
output is distinguishable from random.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
