Use of uninitialized resource in Linux kernel - CVE-2026-90034

 

Use of uninitialized resource in Linux kernel - CVE-2026-90034

Published: September 16, 2026


Vulnerability identifier: #VU150254
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90034
CWE-ID: CWE-908
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows an attacker with physical access to disclose sensitive information.

The vulnerability exists due to use of uninitialized memory in the mdc800 USB driver buffer initialization when receiving shorter messages. An attacker with physical access can send a shorter message to disclose sensitive information.


Affected software

Linux kernel

How to mitigate CVE-2026-90034

Install security update from vendor's repository.


External References

Related Security Bulletins