PT-2026-61399 · Linux+1 · Linux Kernel+1

CVE-2026-64082

·

Published

2026-07-19

·

Updated

2026-09-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description An issue exists where uninitialized stack data is written into a target task's register state during error conditions. In the compat riscv gpr set() function, cregs to regs() is called regardless of whether user regset copyin() fails. Similarly, compat restore sigcontext() calls cregs to regs() even when copy from user() fails. This behavior can lead to register corruption and the potential leakage of kernel stack contents.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-92829
CVE-2026-64082
USN-8593-1
USN-8603-1
USN-8618-1
USN-8663-1
USN-8664-1
USN-8728-1

Affected Products

Linux Kernel
Ubuntu