Use of uninitialized resource in Linux kernel - CVE-2026-89515
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to disclose uninitialized memory contents.
The vulnerability exists due to use of uninitialized memory in scsi_alloc_sgtables() when processing the last unaligned element of a scatterlist requiring DMA padding. A local user can issue an SCSI generic I/O request with an unaligned final scatterlist element to disclose uninitialized memory contents.