CVE-2026-92520
Received
Received - Intake
BaseFortify
Vulnerability report for CVE-2026-92520, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-17
Last updated on: 2026-09-17
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
bpf: Zero queue and stack outputs on lock failure
Queue and stack pop/peek helpers accept an uninitialized output buffer
because the verifier expects the helper to initialize it. The empty-map
error path clears the buffer, but a failed lock acquisition returns
-EBUSY without writing it.
Clear the output before returning -EBUSY so BPF programs cannot observe
uninitialized stack contents after a failed helper call.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | a34a9f1a19afe9c60ca0ea61dfeee63a1c2baac8 |
| Linux | Linux | a34a9f1a19afe9c60ca0ea61dfeee63a1c2baac8 |
| Linux | Linux | a34a9f1a19afe9c60ca0ea61dfeee63a1c2baac8 |
| Linux | Linux | 40e34ea01748e5b8afdd40a172868be1e1ab0ede |
| Linux | Linux | 388c9d3eefaea99828ee5000c693128a5b41ee7c |
| Linux | Linux | acabf5df49aa3a4f9c96200102d893351b511a88 |
| Linux | Linux | e388671635acf470f0986d874389148fd234620b |
| Linux | Linux | 232f0ba4d69263af5912e279fcc32fef2882b1dc |
| Linux | Linux | 5.4.258 |
| Linux | Linux | 5.10.198 |
| Linux | Linux | 5.15.134 |
| Linux | Linux | 6.1.56 |
| Linux | Linux | 6.5.6 |
| Linux | Linux | 6.6 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |