Use of uninitialized resource in Linux kernel - CVE-2026-80970

 

Use of uninitialized resource in Linux kernel - CVE-2026-80970

Published: September 12, 2026


Vulnerability identifier: #VU149418
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80970
CWE-ID: CWE-908
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker with physical access to disclose sensitive information.

The vulnerability exists due to use of uninitialized memory in the ALSA FCP fcp_ioctl_init() response buffer when processing a short or zero-length step-0 USB control transfer. An attacker with physical access can cause a USB device to return a short or zero-length step-0 response to disclose sensitive information.

The disclosure is limited to the step-0 response region.


Affected software

Linux kernel

How to mitigate CVE-2026-80970

Install security update from vendor's repository.


External References

Related Security Bulletins