Use of Uninitialized Variable in Linux kernel - CVE-2026-68461
Published: August 17, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use of uninitialized memory in fwnode_init() in the firmware node handling code when initializing a fwnode_handle allocated on the stack or with a non-zeroing heap allocation. A local user can trigger dereference of an uninitialized secondary pointer to cause a denial of service.
Exploitation requires control over the lifetime and initialization context of the firmware node object.
Affected software
Ubuntu
linux (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
How to mitigate CVE-2026-68461
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
External References
- https://git.kernel.org/stable/c/0198d579948322cda5178b9672d448375a32f947
- https://git.kernel.org/stable/c/173b61c9276c7b3a5fbcc63ae7aafc897fee1e18
- https://git.kernel.org/stable/c/7eba000621fff223dd7bab484d48918c7c77a307
- https://git.kernel.org/stable/c/9c86a1f930bb2ddb85f867b4736716e82a4a4683
- https://git.kernel.org/stable/c/c81e2af41de6a159837c7129a4fc444ac6e48046
- https://git.kernel.org/stable/c/c8542b68ba6ef4f61072098893a3f5b71c569b6c
- https://git.kernel.org/stable/c/f0b4e1cc8ad76baf49d898727eb52e91a4ef0544