Improper initialization in Linux kernel - CVE-2026-93235

 

Improper initialization in Linux kernel - CVE-2026-93235

Published: September 25, 2026


Vulnerability identifier: #VU152159
CSH Severity: Low
CVSS v4: 2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-93235
CWE-ID: CWE-665
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to disclose sensitive information.

The vulnerability exists due to improper initialization of post-EOF data in the F2FS file size extension handling when extending a file across an unaligned EOF boundary. A local user can extend a file across an unaligned EOF boundary to disclose sensitive information.

Stale disk data can be exposed after remounting or crash recovery when metadata is persisted before the zeroed data.


Affected software

Linux kernel

How to mitigate CVE-2026-93235

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins