CVE-2026-93158
Published Sep 17, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: sa2ul - stop probe if context pool creation fails sa_ul_probe() calls sa_init_mem() to create the DMA pool used for security context buffers, but ignores its return value. If pool creation fails, probe still continues with DMA setup, algorithm registration and child population even though later request setup depends on that pool. Stop probing when sa_init_mem() fails, and route that failure to the PM cleanup path without attempting to destroy an uncreated DMA pool.
Is your site exposed to CVE-2026-93158?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/04c46784ec249cac995e31f0691397b82bdaa5fd
https://git.kernel.org/stable/c/304dcd26bfc3ce6771c2bd3b7c0299dcfd5f4e06
https://git.kernel.org/stable/c/91ded4742fcde6ad415c4d8a20e5ea0dcdf4f73e
https://git.kernel.org/stable/c/9907426b438e4dbc8c45138bd440ad6d732d80b7
https://git.kernel.org/stable/c/9a692a6a2b47328a36c8d80c7fbf81da16b6d6b1
https://git.kernel.org/stable/c/b68b35ed97d3e18edb9dea500d88420a95006742
https://git.kernel.org/stable/c/d03f980a25853f6a380895119a572a3bb1194e8d
https://git.kernel.org/stable/c/f72c7837614a9705f8b3021828d49c9f095803ba
Frequently Asked Questions
What is CVE-2026-93158? +
In the Linux kernel, the following vulnerability has been resolved:
crypto: sa2ul - stop probe if context pool creation fails
sa_ul_probe() calls sa_init_mem() to create the DMA pool used for
security context buffers, but ignores its return value. If pool creation
fails, probe still continues with DMA setup, algorithm registration and
child population even though later request setup depends on that pool.
Stop probing when sa_init_mem() fails, and route that failure to the PM
cleanup path without attempting to destroy an uncreated DMA pool.
How do I check if I'm vulnerable to CVE-2026-93158? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.