Use of uninitialized resource in Linux kernel - CVE-2026-97554
Published: September 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose kernel stack contents to the userspace idmap daemon.
The vulnerability exists due to use of uninitialized stack memory in cifs_posix_to_fattr() when processing malformed POSIX directory entries containing invalid SID lengths from an untrusted server. A remote attacker can provide a malformed POSIX directory entry to cause uninitialized SID data to be processed.