Use of uninitialized resource in Linux kernel - CVE-2026-93121
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to cause undefined behavior.
The vulnerability exists due to improper cleanup of an uninitialized dma_fence object in ffs_dmabuf_transfer() when handling an endpoint-disabled or request-allocation failure. A local user can initiate a DMA-buffer transfer that encounters either error condition to cause undefined behavior.