Use of Uninitialized Variable in Linux kernel - CVE-2026-97552
Published: September 28, 2026
Vulnerability details
The vulnerability allows a local privileged user to cause a denial of service.
The vulnerability exists due to use of an uninitialized variable in xfs_defer_finish_one() when processing an item-less pending item during an online repair. A local privileged user can trigger processing of an item-less pending item during an online repair to cause a denial of service.
Only kernels built with CONFIG_XFS_ONLINE_REPAIR are affected.