CVE-2026-92520
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-92520, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-17

Last updated on: 2026-09-17

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: bpf: Zero queue and stack outputs on lock failure Queue and stack pop/peek helpers accept an uninitialized output buffer because the verifier expects the helper to initialize it. The empty-map error path clears the buffer, but a failed lock acquisition returns -EBUSY without writing it. Clear the output before returning -EBUSY so BPF programs cannot observe uninitialized stack contents after a failed helper call.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-17
Last Modified
2026-09-17
Generated
2026-10-10
EPSS Evaluated
2026-10-09
NVD

Affected Vendors & Products

Showing 14 associated CPEs
Vendor Product Version / Range
Linux Linux a34a9f1a19afe9c60ca0ea61dfeee63a1c2baac8
Linux Linux a34a9f1a19afe9c60ca0ea61dfeee63a1c2baac8
Linux Linux a34a9f1a19afe9c60ca0ea61dfeee63a1c2baac8
Linux Linux 40e34ea01748e5b8afdd40a172868be1e1ab0ede
Linux Linux 388c9d3eefaea99828ee5000c693128a5b41ee7c
Linux Linux acabf5df49aa3a4f9c96200102d893351b511a88
Linux Linux e388671635acf470f0986d874389148fd234620b
Linux Linux 232f0ba4d69263af5912e279fcc32fef2882b1dc
Linux Linux 5.4.258
Linux Linux 5.10.198
Linux Linux 5.15.134
Linux Linux 6.1.56
Linux Linux 6.5.6
Linux Linux 6.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
AI Quick Actions have not been generated yet.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92520. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart