Use of uninitialized resource in Linux kernel - CVE-2026-90221
Published: September 18, 2026
Vulnerability details
The vulnerability allows a local user to read uninitialized slab memory.
The vulnerability exists due to improper length validation in the nci_core_init_rsp_packet_v1() and nci_core_init_rsp_packet_v2() CORE_INIT_RSP parsers when processing a malformed CORE_INIT_RSP packet injected through virtual_ncidev. A local user can inject a malformed response with an inflated number of supported RF interfaces to read uninitialized slab memory.
Affected software
How to mitigate CVE-2026-90221
External References
- https://git.kernel.org/stable/c/2f434478771a4ebdd535033561c0590bcde39753
- https://git.kernel.org/stable/c/4f0483bbcdaccc9d4aee30df7351863334cecfa7
- https://git.kernel.org/stable/c/5487f04c1ccbfa15aa6e531eb1ec9c9ec9c7bf31
- https://git.kernel.org/stable/c/7d44b897bff84edcd4814899314d661ad4956a8e
- https://git.kernel.org/stable/c/baed3fdf6ed2195c56f25ae18a086b938dcd3983
- https://git.kernel.org/stable/c/bbe68e8249e2c76d65adfd9224fa95f1ca0fbe4e
- https://git.kernel.org/stable/c/d56575a2595ee1f597f39e8a1cfb67ed3501678d