Use of uninitialized resource in Linux kernel - CVE-2026-89616

 

Use of uninitialized resource in Linux kernel - CVE-2026-89616

Published: September 12, 2026


Vulnerability identifier: #VU149193
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-89616
CWE-ID: CWE-908
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper initialization in ni_read_frame() when reading a crafted compressed NTFS file. A local user can trigger partial LZNT decompression to disclose sensitive information.

Disclosed data can include recently freed kernel page memory and kernel pointers.


Affected software

Linux kernel

How to mitigate CVE-2026-89616

Install security update from vendor's repository.


External References

Related Security Bulletins