Use of Uninitialized Variable in Linux kernel - CVE-2026-98001
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to use of uninitialized stack memory in ltc428_clk_provider_setup() when initializing the ltc4282 clock provider. A local privileged user can trigger initialization of the ltc4282 clock provider to cause a denial of service.
The issue is exposed when CONFIG_INIT_STACK_ALL_PATTERN or CONFIG_INIT_STACK_NONE is enabled.