Use of Uninitialized Variable in Linux kernel - CVE-2026-93249
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to use of an uninitialized structure member in aml_spisg_clk_init() when initializing the Amlogic SPISG clock driver. A local user can trigger clock driver initialization to cause a denial of service.
The issue is exposed when CONFIG_INIT_STACK_ALL_PATTERN or CONFIG_INIT_STACK_NONE is enabled.