Use of uninitialized resource in Linux kernel - CVE-2026-90034
Published: September 16, 2026
Vulnerability identifier: #VU150254
CSH Severity: Low
CVSS v4: 2.4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-90034
CWE-ID: CWE-908
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows an attacker with physical access to disclose sensitive information.
The vulnerability exists due to use of uninitialized memory in the mdc800 USB driver buffer initialization when receiving shorter messages. An attacker with physical access can send a shorter message to disclose sensitive information.
Affected software
Linux kernel
How to mitigate CVE-2026-90034
Install security update from vendor's repository.
External References
- https://git.kernel.org/stable/c/2430eb81e44111b30eeb5273bbcf8b24ca517ef9
- https://git.kernel.org/stable/c/2df8f7720ed91f1aad4f128553b6e90c7c5fac1e
- https://git.kernel.org/stable/c/553c375e86a49882e95840565512e17bff31cc3a
- https://git.kernel.org/stable/c/67c6726dd6048a2781aa43a2bf9fcf1e16ee3a7d
- https://git.kernel.org/stable/c/6c601410d1a9ae645f604fe2f61b9f4942c77dfb
- https://git.kernel.org/stable/c/838455cc8bfe1278150d1d776529edea6cd4c1dd
- https://git.kernel.org/stable/c/8c38049879f2108f57c98f03cc7f3db51a12bdab
- https://git.kernel.org/stable/c/e22428f0c038c23109c0383a235aa607b0cd4c95