CVE-2026-93161: crypto: qat - clear AES key schedule from stack
Published Sep 17, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
crypto: qat - clear AES key schedule from stack
qatalgxtsreversekey() expands the forward XTS AES key on the stack. That schedule contains key material and can remain in the stack frame.
Clear the temporary cryptoaesctx with memzeroexplicit() after the copy.
Affected Software
1 affected component
Linux Kernel
Event History
Sep 17, 2026
CVE Published
via MITRE·04:11 PM
Data Sourced
via MITRE·04:11 PM
Description
Frequently Asked Questions
1
What systems are exposed to this issue?
Linux kernel systems using the QAT crypto code path that invokes qat_alg_xts_reverse_key() may retain an expanded XTS AES key schedule in a stack frame.
2
What does the fix change?
The fix explicitly clears the temporary crypto_aes_ctx holding the expanded AES key schedule with memzero_explicit() after the schedule is copied.