CVE-2026-64306: crypto: drbg - Fix returning success on failure in CTR_DRBG
crypto: drbg - Fix returning success on failure in CTRDRBG
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.6.145.2-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-64306?
The severity of CVE-2026-64306 is classified as medium with a score of 5.5.
How do I fix CVE-2026-64306?
To fix CVE-2026-64306, you should update to the latest version of the Linux kernel that has implemented the fix.
What is the impact of CVE-2026-64306?
The impact of CVE-2026-64306 includes the potential for an attacker to exploit the uninitialized output buffer, leading to unauthorized access to sensitive data.
What systems are affected by CVE-2026-64306?
CVE-2026-64306 affects the Linux kernel and the Microsoft azl3 kernel version 6.6.144.1-1.
What type of vulnerability is CVE-2026-64306?
CVE-2026-64306 is a cryptographic vulnerability related to the deterministic random bit generator (DRBG) in the Linux kernel.