SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-64082

HIGH · CVSS 7.8 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-07-19 · Last synced 2026-08-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel, specifically in the RISC-V architecture, where uninitialized stack variables can lead to register corruption during error handling in certain functions. This flaw may allow for the leakage of sensitive kernel stack data and compromise the integrity of the target task's register state. Organizations using Linux on RISC-V systems should prioritize addressing this vulnerability to mitigate potential security risks.

CVE
CVE-2026-64082
Severity
HIGH
CVSS
7.8
EPSS
0.12%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: riscv: Fix register corruption from uninitialized cregs on error compat_riscv_gpr_set() calls cregs_to_regs() unconditionally, even when user_regset_copyin() fails. Since cregs is an uninitialized stack variable, a copyin failure causes uninitialized stack data to be written into the target task's pt_regs, corrupting its register state and potentially leaking kernel stack contents. compat_restore_sigcontext() has the same issue: it calls cregs_to_regs() even when __copy_from_user() fails, leading to the same corruption of the signal-returning task's register state on error. Only call cregs_to_regs() when the user copy succeeds.