Improper initialization in Linux kernel - CVE-2026-93230
Published: September 25, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to improper initialization in gigantic bootmem HugeTLB struct pages when page allocator setup evaluates zone contiguity before the struct pages are initialized. A local privileged user can boot a system with a bootmem HugeTLB region marked noinit to cause a denial of service.