Use of Uninitialized Variable in Linux kernel - CVE-2026-92520
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to disclose uninitialized stack contents.
The vulnerability exists due to use of an uninitialized output buffer in BPF queue and stack pop/peek helpers when a lock acquisition fails. A local user can invoke the affected helpers during a failed lock acquisition to disclose uninitialized stack contents.