The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux siginfo_t. It did not first zero the stack struct.
An unprivileged user may observe 104 bytes of uninitialized kernel stack data, which may contain sensitive information.
CVE-2026-49424
NONE
EPSS 0.15%
Updated Aug 19, 2026
Linux
freebsd:freebsd
CVE Details
CVE ID
CVE-2026-49424
Published Date
Aug 19, 2026
Vendor
Linux
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.15%
Likelihood of exploitation in next 30 days
Percentile:
4.7th percentile (higher than 4.7% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory