OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-93801

HIGH · CVSS 7 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The vulnerability in the Linux kernel affects the stack-allocated `cifs_open_info_data`, which may contain uninitialized random data, potentially leading to incorrect field values if not explicitly set. This could result in unpredictable behavior or security issues in applications relying on the CIFS protocol. Linux system administrators and developers utilizing CIFS should prioritize addressing this vulnerability to ensure the integrity and reliability of their systems.

CVE
CVE-2026-93801
Severity
HIGH
CVSS
7
EPSS
0.12%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: smb/client: zero-initialize stack-allocated cifs_open_info_data Stack-allocated cifs_open_info_data may contain random data. This can make some fields have wrong value if they are not set later.