In the Linux kernel, the following vulnerability has been resolved:
fs: Fix uninitialized 'offp' in statmount_string()
In statmount_string(), most flags assign an output offset pointer (offp) which is later updated with the string offset. However, the STATMOUNT_MNT_UIDMAP and STATMOUNT_MNT_GIDMAP cases directly set the struct fields instead of using offp. This leaves offp uninitialized, leading to a possible uninitialized dereference when *offp is updated.
Fix it by assigning offp for UIDMAP and GIDMAP as well, keeping the code path consistent.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Dec 16, 2025 |
| Ubuntu | — | Upgrade linux-image-6.17.0-1009-aws-64kUpgrade linux-image-virtual-6.17Upgrade linux-image-virtual-hwe-24.04Upgrade linux-image-virtualUpgrade linux-image-6.17.0-1009-awsUpgrade linux-image-genericUpgrade linux-image-realtime-6.17Upgrade linux-image-gcp-64kUpgrade linux-image-aws-6.17Upgrade linux-image-gcp-6.17Upgrade linux-image-6.17.0-1009-oracleUpgrade linux-image-oem-24.04Upgrade linux-image-6.17.0-1009-gcpUpgrade linux-image-aws-64kUpgrade linux-image-gcp-64k-6.17Upgrade linux-image-realtimeUpgrade linux-image-oracleUpgrade linux-image-6.17.0-1009-oracle-64kUpgrade linux-image-6.17.0-1009-gcp-64kUpgrade linux-image-6.17.0-19-generic-64kUpgrade linux-image-oracle-64k-6.17Upgrade linux-image-gcpUpgrade linux-image-generic-6.17Upgrade linux-image-raspi-6.17Upgrade linux-image-6.17.0-19-genericUpgrade linux-image-oem-24.04aUpgrade linux-image-oracle-64kUpgrade linux-image-raspiUpgrade linux-image-azure-6.17Upgrade linux-image-6.17.0-1010-azureUpgrade linux-image-oem-24.04cUpgrade linux-image-generic-64kUpgrade linux-image-generic-64k-hwe-24.04Upgrade linux-image-generic-64k-6.17Upgrade linux-image-aws-64k-6.17Upgrade linux-image-oem-6.17Upgrade linux-image-oem-24.04dUpgrade linux-image-oem-24.04bUpgrade linux-image-6.17.0-1010-raspiUpgrade linux-image-oracle-6.17Upgrade linux-image-6.17.0-1008-realtimeUpgrade linux-image-generic-hwe-24.04Upgrade linux-image-6.17.0-1017-oemUpgrade linux-image-azureUpgrade linux-image-awsUpgrade linux-image-realtime-hwe-24.04 | Mar 17, 2026 | Dec 16, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub