CVE-2026-64082

In the Linux kernel, the following vulnerability has been resolved: riscv: Fix register corruption from uninitialized cregs on error compat_riscv_gpr_set() calls cregs_to_regs() unconditionally, even when user_regset_copyin() fails. Since cregs is an uninitialized stack variable, a copyin failure causes uninitialized stack data to be written into the target task's pt_regs, corrupting its register state and potentially leaking kernel stack contents. compat_restore_sigcontext() has the same issue: it calls cregs_to_regs() even when __copy_from_user() fails, leading to the same corruption of the signal-returning task's register state on error. Only call cregs_to_regs() when the user copy succeeds.
Configurations

No configuration.

History

20 Jul 2026, 15:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

19 Jul 2026, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-19 16:17

Updated : 2026-07-20 15:17


NVD link : CVE-2026-64082

Mitre link : CVE-2026-64082

CVE.ORG link : CVE-2026-64082


JSON object : View

Products Affected

No product.

CWE

No CWE.