Use of Uninitialized Variable in Linux kernel - CVE-2026-97907
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause firmware parsing to fail.
The vulnerability exists due to use of an uninitialized variable in rtlbt_parse_firmware_v2() when parsing firmware format v2 security headers with a zero chip key ID. A local user can trigger parsing of firmware containing a security header to cause firmware parsing to fail.