Back

MEDIUM

rseq: Fix using an uninitialized stack variable in rseq_exit_user_update()

Published Jun 25, 2026

Description

There is an bug in which an uninitialized stack variable is used in rseq_exit_user_update() as reported by syzbot:

BUG: KMSAN: kernel-infoleak in rseq_set_ids_get_csaddr include/linux/rseq_entry.h:502 [inline]

The local variable:

struct rseq_ids ids = { .cpu_id = task_cpu(t), .mm_cid = task_mm_cid(t), .node_id = cpu_to_node(ids.cpu_id), };

According to the C standard, the evaluation order of expressions in an initializer list is indeterminately sequenced. The compiler (Clang, in this KMSAN build) evaluates `cpu_to_node(ids.cpu_id)` *before* `ids.cpu_id` is initialized with `task_cpu(t)`.

This is fixed by moving the assignment of ids.node_id outside the structure initialization.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Jun 25, 2026
Updated Jun 25, 2026
Reserved Jun 9, 2026

CISA Vulnrichment

No data

NVD

Status Analyzed
Modified Jul 7, 2026

Red Hat

Public date Jun 25, 2026
Bugzilla 2492767

ENISA EUVD

Assigner Linux
Published Jun 25, 2026
Updated Jun 25, 2026

GitHub

No data