Use of Uninitialized Variable in Linux kernel - CVE-2026-89505
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use of an uninitialized pointer in uverbs_get_handler_fn() when processing malformed provider input through the legacy write() path. A local user can supply malformed provider input to trigger the pointer dereference and cause a denial of service.