Medium severity5.5NVD Advisory· Published Aug 19, 2026· Updated Aug 31, 2026
CVE-2026-49424
CVE-2026-49424
Description
The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux siginfo_t. It did not first zero the stack struct.
An unprivileged user may observe 104 bytes of uninitialized kernel stack data, which may contain sensitive information.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
1- security.freebsd.org/advisories/FreeBSD-SA-26:47.linux.ascnvdVendor Advisory
News mentions
0No linked articles in our index yet.