Use of Uninitialized Variable in Linux kernel - CVE-2026-97965
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local privileged user to disclose uninitialized kernel stack data.
The vulnerability exists due to use of an uninitialized stack variable in vxlan_xmit_one() when transmitting a packet through a VXLAN device using external tunnel information that lacks the IP_TUNNEL_VXLAN_OPT_BIT flag. A local privileged user can transmit such a packet to disclose uninitialized kernel stack data.
The VXLAN device must be configured with both VXLAN_F_COLLECT_METADATA and VXLAN_F_GBP.