0.0
NA
CVE-2026-93160
crypto: atmel-ecc - reject hardware ECDH without a public key
Description

In the Linux kernel, the following vulnerability has been resolved: crypto: atmel-ecc - reject hardware ECDH without a public key The hardware ECDH path in atmel_ecdh_compute_shared_secret() uses the private key stored in the device. However, the public key is cached only after atmel_ecdh_set_secret() successfully generated that private key for the current tfm. atmel_ecdh_generate_public_key() already rejects requests when no public key is cached. Add the same check to atmel_ecdh_compute_shared_secret() to prevent the device from using a private key that was not generated for the current tfm.

INFO

Published Date :

Sept. 17, 2026, 5:18 p.m.

Last Modified :

Sept. 17, 2026, 5:18 p.m.

Remotely Exploit :

No

Source :

416baaa9-dc9f-4396-8d5f-8c081fb06d67
Affected Products

The following products are affected by CVE-2026-93160 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Linux linux_kernel
Solution
Apply the kernel patch to reject hardware ECDH without a public key.
  • Update the Linux kernel to the latest version.
  • Apply the specific patch for atmel-ecc.
  • Verify ECDH functionality post-update.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2026-93160 is associated with the following CWEs:

Common Attack Pattern Enumeration and Classification (CAPEC)

Common Attack Pattern Enumeration and Classification (CAPEC) stores attack patterns, which are descriptions of the common attributes and approaches employed by adversaries to exploit the CVE-2026-93160 weaknesses.

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2026-93160 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2026-93160 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • New CVE Received by 416baaa9-dc9f-4396-8d5f-8c081fb06d67

    Sep. 17, 2026

    Action Type Old Value New Value
    Added Description In the Linux kernel, the following vulnerability has been resolved: crypto: atmel-ecc - reject hardware ECDH without a public key The hardware ECDH path in atmel_ecdh_compute_shared_secret() uses the private key stored in the device. However, the public key is cached only after atmel_ecdh_set_secret() successfully generated that private key for the current tfm. atmel_ecdh_generate_public_key() already rejects requests when no public key is cached. Add the same check to atmel_ecdh_compute_shared_secret() to prevent the device from using a private key that was not generated for the current tfm.
    Added Affected New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/93xxx/CVE-2026-93160.json">CVE-2026-93160</a>
    Added Reference https://git.kernel.org/stable/c/2b40bab362d2b598f34e5ccd4694cedc3c2553d4
    Added Reference https://git.kernel.org/stable/c/33241f198287960bba5fc2251400896762650bfa
    Added Reference https://git.kernel.org/stable/c/3ea8b780d68f02fe235c5051ce8ac4b4940b9259
    Added Reference https://git.kernel.org/stable/c/5e33791dfcc6459e402a524669093cd953d5b2df
    Added Reference https://git.kernel.org/stable/c/6457162f74f45284ade2da644a4f0c54758ac0a6
    Added Reference https://git.kernel.org/stable/c/add28e9988902d29ea93f4869280b4a16a049ea5
    Added Reference https://git.kernel.org/stable/c/e64d6f1aae8c837cb3f0446bf44108226d7370f4
    Added Reference https://git.kernel.org/stable/c/f240f9b588f4e2de89822adebf560a96b5d263ed
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.