Use of Uninitialized Variable in Linux kernel - CVE-2026-89910
Published: September 17, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information and modify data.
The vulnerability exists due to use of an uninitialized stack variable in dmsintc_inject_irq() in the LoongArch KVM dmsintc component when injecting interrupts. A local user can trigger IRQ injection to disclose sensitive information and modify data.