Use of uninitialized resource in Linux kernel - CVE-2026-89483
Published: September 12, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to use of uninitialized memory in the NVMe discard fallback page when processing discard commands. A local user can trigger a discard command that causes uninitialized DSM payload data to be sent to the controller to disclose sensitive information.
Exploitation requires the discard-range allocation to fail under memory pressure.