Use of uninitialized resource in Linux kernel - CVE-2026-93174
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to disclose stale heap contents.
The vulnerability exists due to incomplete copying of per-CPU map value padding in copy_map_value_long() when processing UAPI LOOKUP_ELEM operations on per-CPU maps. A local user can invoke a UAPI lookup operation on a per-CPU map with a value size that requires padding to disclose stale heap contents.
The issue also affects bpf_iter for per-CPU maps.
Affected software
How to mitigate CVE-2026-93174
External References
- https://git.kernel.org/stable/c/003bf840ed3326bd01396ce7d5b431cef0d371e7
- https://git.kernel.org/stable/c/5e9f69829835521aa2942d1d14bd0990fbc6991e
- https://git.kernel.org/stable/c/7cf9cd98cf6f0df3befc167ca6b54c07014d71de
- https://git.kernel.org/stable/c/953e85da53541a8dc3e7ad4e8532f29a34a32eae
- https://git.kernel.org/stable/c/ff3f22ed8d2f350b4c24ee26e33daea5f08d58ef