CVE-2026-72151: tpm: tpm2-sessions: wait for async KPP completion in tpm_buf_append_salt
In the Linux kernel, the following vulnerability has been resolved:
tpm: tpm2-sessions: wait for async KPP completion in tpmbufappendsalt
tpmbufappendsalt() in drivers/char/tpm/tpm2-sessions.c calls cryptokppgeneratepublickey() and cryptokppcomputesharedsecret() without installing a completion callback, discards both return values, and immediately frees the kpprequest via kpprequestfree(). When the resolved ecdh-nist-p256 KPP backend is asynchronous (atmel-ecc, HPRE, keembay-ocs), either operation returns -EINPROGRESS and the deferred completion worker dereferences the freed request.
The path fires automatically from the hwrngfillfn kernel thread via tpmgetrandom -> tpm2getrandom -> tpm2startauthsession -> tpmbufappendsalt on every entropy poll, without any userland action.
Install cryptoreqdone as the completion callback, wrap both KPP operations in cryptowaitreq(), and propagate errors to the caller. The wait is a no-op for synchronous backends.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72151?
The severity of CVE-2026-72151 is rated at 75, indicating it is a significant risk.
How do I fix CVE-2026-72151?
To fix CVE-2026-72151, update to the latest version of the Linux kernel that addresses this vulnerability.
What systems are affected by CVE-2026-72151?
CVE-2026-72151 affects Linux systems using the TPM2 sessions functionality in their kernel.
What type of vulnerability is CVE-2026-72151?
CVE-2026-72151 is a vulnerability related to the improper handling of asynchronous Key Pair Processing in the Linux kernel.
When was CVE-2026-72151 published?
CVE-2026-72151 was published on August 15, 2026.