The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux siginfo_t. It did not first zero the stack struct.
An unprivileged user may observe 104 bytes of uninitialized kernel stack data, which may contain sensitive information.
Metrics
Affected Vendors & Products
References
History
Wed, 19 Aug 2026 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux siginfo_t. It did not first zero the stack struct. An unprivileged user may observe 104 bytes of uninitialized kernel stack data, which may contain sensitive information. | |
| Title | Kernel stack disclosure in Linux compatibility layer | |
| Weaknesses | CWE-908 | |
| References |
|
Status: PUBLISHED
Assigner: freebsd
Published:
Updated: 2026-08-19T07:08:35.691Z
Reserved: 2026-05-29T20:24:28.616Z
Link: CVE-2026-49424
No data.
Status : Received
Published: 2026-08-19T08:17:12.060
Modified: 2026-08-19T08:17:12.060
Link: CVE-2026-49424
No data.
OpenCVE Enrichment
No data.