rseq: Fix using an uninitialized stack variable in rseq_exit_user_update()
Published Jun 25, 2026
5.5
MEDIUMCVSS 3.1
EPSS 0.11%
Description
There is an bug in which an uninitialized stack variable is used in rseq_exit_user_update() as reported by syzbot:
BUG: KMSAN: kernel-infoleak in rseq_set_ids_get_csaddr include/linux/rseq_entry.h:502 [inline]
The local variable:
struct rseq_ids ids = { .cpu_id = task_cpu(t), .mm_cid = task_mm_cid(t), .node_id = cpu_to_node(ids.cpu_id), };
According to the C standard, the evaluation order of expressions in an initializer list is indeterminately sequenced. The compiler (Clang, in this KMSAN build) evaluates `cpu_to_node(ids.cpu_id)` *before* `ids.cpu_id` is initialized with `task_cpu(t)`.
This is fixed by moving the assignment of ids.node_id outside the structure initialization.
Affected products
-
Affected
- ≥ 7.0.10, < 7.0.13
-
Affected
- ≥ , <
- ≥ , <
- ≥ 7.0.10 · < 7.0.13
- 7.1
- 7.1
- 7.1
- 7.1
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (8)
- https://access.redhat.com/security/cve/CVE-2026-53243 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2492767 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-39194 Advisory
- https://git.kernel.org/stable/c/6d99479799c69c3cb588fcda19c81d8f61d64ecd Patch
- https://git.kernel.org/stable/c/e12d20a63b61aaf9de4772effccf42cc9a003e58 Patch
- https://lore.kernel.org/linux-cve-announce/2026062511-CVE-2026-53243-0e70@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-53243
- https://www.cve.org/CVERecord?id=CVE-2026-53243
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
No data
GitHub
No data