Use of Uninitialized Variable in Linux kernel - CVE-2026-97610
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local user to cause incorrect error reporting.
The vulnerability exists due to use of an uninitialized return value in netfs_unbuffered_write() when preparing the first subrequest for a synchronous write fails. A local user can trigger a synchronous CIFS write for which request preparation fails to cause incorrect error reporting.
The issue is reachable when cifs_prepare_write() fails to reopen the file or obtain credits.