Executive brief
A vulnerability was identified in the Linux kernel's hamradio driver that could allow an attacker to read uninitialized memory. This component is used for amateur radio networking. While the practical impact is limited to specific hardware configurations, it could potentially lead to minor data leakage or system instability.
Technical details
A vulnerability exists in the sixpack_receive_buf() function within the net: hamradio: 6pack driver of the Linux kernel. The function fails to properly advance the data pointer (cp) when encountering TTY error flags in the flags buffer (fp). Consequently, it passes the original data count, including bytes marked with errors, to sixpack_decode(). Because the TTY layer does not guarantee that data at error positions is initialized, this results in an uninitialized-value read as reported by KMSAN. An attacker with local access could potentially exploit this to leak information from kernel memory. The issue has been resolved by ensuring the data pointer is advanced correctly and only valid bytes are processed.
Affected products
- Linux Linux Kernel v2.6.12-rc2 to v6.9.3
Timeline
- 2026-04-08: other: Patch authored
- 2026-06-24: advisory: CVE published
References
- https://git.kernel.org/stable/c/1d3abf0c3ddeefc6f6d913aa129acc06fce8240a
- https://git.kernel.org/stable/c/2951656b0de00153f2687f3a093890bce72b6215
- https://git.kernel.org/stable/c/578f3aba427c938fecfa0d8c83d9acb213a9b24a
- https://git.kernel.org/stable/c/987af7625ceb1ee59d70eb0abd7af11c75e45d79
- https://git.kernel.org/stable/c/bf9a38803b2626b01cc769aaf13485d8650f576f
- https://git.kernel.org/stable/c/d4cceb5184538613572fb79319453f281b1eeacb
- https://git.kernel.org/stable/c/d9ce2a4b679122397d7f35bad7be46913ad1ca80