CVE-2026-52936: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.1% chance of exploitation in the next 30 days.
In the Linux kernel, the following vulnerability has been resolved: crypto: jitterentropy - replace long-held spinlock with mutex jent_kcapi_random() serializes the shared jitterentropy state, but it currently holds a spinlock across the jent_read_entropy() call. That path performs expensive jitter collection and SHA3 conditioning, so parallel readers can trigger stalls as contending waiters spin for the same lock. To prevent non-preemptible lock hold, replace rng->jent_lock with a mutex so contended readers sleep instead of spinning on a shared lock held across expensive entropy generation.
Affected products
- Linux Linux Kernel: from 4.2, before 6.6.141 (fixed in 6.6.141); from 6.7, before 6.12.91 (fixed in 6.12.91); from 6.13, before 6.18.33 (fixed in 6.18.33); from 6.19, before 7.0.10 (fixed in 7.0.10)
Published 2026-06-24. Last modified 2026-07-08.