Improper initialization in Linux kernel - CVE-2026-97963
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to trigger undefined behavior.
The vulnerability exists due to improper initialization in the stmmac driver's ptp_lock when offloading a TAPRIO schedule while the interface is down. A local user can configure a TAPRIO schedule to trigger undefined behavior.
The issue occurs when the interface has never been opened.