{"id":"CVE-2026-90300","published":"2026-09-17T17:17:27.503","lastModified":"2026-09-17T17:17:27.503","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Clear buf on error in __bpf_get_task_stack\n\nBoth bpf_get_task_stack and bpf_get_task_stack_sleepable helpers that\nuse __bpf_get_task_stack have buf defined as ARG_PTR_TO_UNINIT_MEM\nargument and we should initialize the buf on every return path.\n\nAdding missing buf memset for __bpf_get_task_stack fail paths. This\nprovides deterministic buffer contents, which is useful when the buffer\nis used directly as a map key.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":[],"vendors":[],"products":[],"references":[{"url":"https://git.kernel.org/stable/c/f523359c4789bb0396d2d642464a6e2fd4f2299d","tags":[]},{"url":"https://git.kernel.org/stable/c/f5d242825ca417bb6afe35fde6e8880f97ca43fb","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}