Use of Uninitialized Variable in Linux kernel - CVE-2026-97929
Published: September 28, 2026
Vulnerability details
The vulnerability allows an attacker with physical access to disclose sensitive information.
The vulnerability exists due to use of uninitialized heap data in the i_usx2y_in04_int() interrupt callback when handling a short transfer from a USB device. An attacker with physical access can cause a short transfer to disclose sensitive information.
The uninitialized data is copied to the mmap-accessible ctl_snapshot[] array.