๐Ÿ” CVE Alert

CVE-2026-64082

UNKNOWN 0.0

riscv: Fix register corruption from uninitialized cregs on error

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: riscv: Fix register corruption from uninitialized cregs on error compat_riscv_gpr_set() calls cregs_to_regs() unconditionally, even when user_regset_copyin() fails. Since cregs is an uninitialized stack variable, a copyin failure causes uninitialized stack data to be written into the target task's pt_regs, corrupting its register state and potentially leaking kernel stack contents. compat_restore_sigcontext() has the same issue: it calls cregs_to_regs() even when __copy_from_user() fails, leading to the same corruption of the signal-returning task's register state on error. Only call cregs_to_regs() when the user copy succeeds.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 19, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
7383ee05314be58f8f9f018ee0ac53bef3808aea < 9e020156833f1ad0d425a1e3d85b65639f1c1c50 7383ee05314be58f8f9f018ee0ac53bef3808aea < 6ebcbb53fc9bc30843054ed99fd60b8e542628f4
Linux / Linux
5.19

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/9e020156833f1ad0d425a1e3d85b65639f1c1c50 git.kernel.org: https://git.kernel.org/stable/c/6ebcbb53fc9bc30843054ed99fd60b8e542628f4