Improper Initialization in Linux kernel - CVE-2026-43408
Published: May 8, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to improper initialization in ceph_mdsc_build_path() callers when handling error paths after building Ceph path information. A local user can trigger a failed ceph_mdsc_build_path() call and subsequent ceph_mdsc_free_path_info() use of an uninitialized ceph_path_info structure to cause a denial of service.
The issue may occur because ceph_mdsc_build_path() initializes the structure only on success, while callers may still free it after an error.