Use of uninitialized resource in Linux kernel - CVE-2026-80970
Published: September 12, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to disclose sensitive information.
The vulnerability exists due to use of uninitialized memory in the ALSA FCP fcp_ioctl_init() response buffer when processing a short or zero-length step-0 USB control transfer. An attacker with physical access can cause a USB device to return a short or zero-length step-0 response to disclose sensitive information.
The disclosure is limited to the step-0 response region.