Use of Uninitialized Variable in Linux kernel - CVE-2026-64088
Published: July 20, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to uninitialized memory exposure in batadv_send_other_tt_response() and batadv_tt_prepare_tvlv_global_data() when handling tt changeset response data. A remote attacker can trigger processing of an oversized tt_buff_len value to disclose sensitive information.
The issue is caused by a signed integer field wrapping to a negative value and then being widened with sign extension, resulting in a fully allocated buffer that is only partially initialized.
How to mitigate CVE-2026-64088
Sources
- https://git.kernel.org/stable/c/32edd2a28e112064020a2f319a8cb8a9e5a09767
- https://git.kernel.org/stable/c/33e5ede7ce6d92e531920d4bbd6d3e18ef1c6430
- https://git.kernel.org/stable/c/3c96dff00998314983b68a3e7caac07a66ebe496
- https://git.kernel.org/stable/c/4c4c2f340f4c27373bfcac8dc5032ce7bb474e47
- https://git.kernel.org/stable/c/4dab98961426d0cf6a1599cda6950b7596ca2fcd
- https://git.kernel.org/stable/c/730de8733dd90f70d7580a9b329b971f8e1474a2
- https://git.kernel.org/stable/c/b64963a2ceeb7529310b6cf253a1e540784422f4
- https://git.kernel.org/stable/c/ed28ead3420c373a7928622f114bc6168075d1e1