CWE-908— Use of Uninitialized Resource
The product uses or accesses a resource that has not been initialized.— MITRE CWE catalog
930 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-908page 10 of 19
- CVE-2026-69672MEDIUMCVSS 5.5EG 5.52026-09-08
Use of uninitialized resource in Windows DNS allows an authorized attacker to disclose information locally.
- CVE-2026-69288MEDIUMCVSS 5.5EG 5.52026-09-08
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
- CVE-2026-68873MEDIUMCVSS 5.5EG 5.52026-09-08
Insertion of sensitive information into log file in Windows Program Compatibility Assistant Service allows an authorized attacker to disclose information locally.
- CVE-2026-68852MEDIUMCVSS 5.5EG 5.52026-09-08
Use of uninitialized resource in Microsoft Account allows an authorized attacker to disclose information locally.
- CVE-2026-70290MEDIUMCVSS 5.5EG 5.52026-09-08
Use of uninitialized resource in Windows Win32 Kernel Subsystem allows an authorized attacker to disclose information locally.
- CVE-2026-72945MEDIUMCVSS 5.5EG 5.52026-09-08
Use of uninitialized resource in Windows Task Scheduler allows an authorized attacker to disclose information locally.
- CVE-2026-69770MEDIUMCVSS 5.5EG 5.52026-09-08
Use of uninitialized resource in Windows Spaceport.sys allows an authorized attacker to disclose information locally.
- CVE-2026-58084MEDIUMCVSS 5.5EG 5.52026-08-19
To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the current time for the timer's clock. For a timer using CLOCK_TAI this can fail when no TAI offset has been configured, but the error return was n…
- CVE-2026-49425MEDIUMCVSS 5.5EG 5.52026-08-19
The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct. It did not first zero the stack struct. An unprivileged user may observe a small amount of uninitialized kernel stack data, which may c…
- CVE-2026-49424MEDIUMCVSS 5.5EG 5.52026-08-19
The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux siginfo_t. It did not first zero the stack struct. An unprivileged user may observe 104 bytes of uninitialized kernel stack data, which m…
- CVE-2026-68799MEDIUMCVSS 5.5EG 5.52026-08-11
Use of uninitialized resource in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
- CVE-2026-62709MEDIUMCVSS 5.5EG 5.52026-08-11
Use of uninitialized resource in Windows GDI+ allows an authorized attacker to disclose information locally.
- CVE-2026-70317MEDIUMCVSS 5.5EG 5.52026-08-11
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
- CVE-2026-62740MEDIUMCVSS 5.5EG 5.52026-08-11
Use of uninitialized resource in Windows Imaging Component allows an authorized attacker to disclose information locally.
- CVE-2026-59137MEDIUMCVSS 5.5EG 5.52026-08-11
Use of uninitialized resource in Windows Event Logging Service allows an authorized attacker to disclose information locally.
- CVE-2026-59136MEDIUMCVSS 5.5EG 5.52026-08-11
Use of uninitialized resource in Microsoft COM for Windows allows an authorized attacker to disclose information locally.
- CVE-2026-70631MEDIUMCVSS 5.5EG 5.52026-08-06
FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply…
- CVE-2026-70630MEDIUMCVSS 5.5EG 5.52026-08-06
FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by sup…
- CVE-2026-70629MEDIUMCVSS 5.5EG 5.52026-08-06
FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted vid…
- CVE-2026-64360MEDIUMCVSS 5.5EG 5.52026-07-25
In the Linux kernel, the following vulnerability has been resolved: hfs/hfsplus: zero-initialize buffer in hfs_bnode_read hfs_bnode_read() can return early without writing to the output buffer when is_bnode_offset_valid() fails or when c…
- CVE-2026-64309MEDIUMCVSS 5.5EG 5.52026-07-25
In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT) Sashiko notes: > if SEV initialization fails and KVM is actively running normal VMs, could a > userspace proce…
- CVE-2026-64220MEDIUMCVSS 5.5EG 5.52026-07-24
In the Linux kernel, the following vulnerability has been resolved: device property: set fwnode->secondary to NULL in fwnode_init() If a firmware node is allocated on the stack (for instance: temporary software node whose life-time we co…
- CVE-2026-64130MEDIUMCVSS 5.5EG 5.52026-07-19
In the Linux kernel, the following vulnerability has been resolved: mm/page_alloc: fix initialization of tags of the huge zero folio with init_on_free __GFP_ZEROTAGS semantics are currently a bit weird, but effectively this flag is only …
- CVE-2026-53379MEDIUMCVSS 5.5EG 5.52026-07-19
In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov8856: free control handler on error in ov8856_init_controls() The control handler wasn't freed if adding controls failed, add an error exit label and conve…
- CVE-2026-57084MEDIUMCVSS 5.5EG 5.52026-07-14
Use of uninitialized resource in Windows File Explorer allows an unauthorized attacker to disclose information locally.
- CVE-2026-57083MEDIUMCVSS 5.5EG 5.52026-07-14
Use of uninitialized resource in Microsoft Windows Codecs Library allows an unauthorized attacker to disclose information locally.
- CVE-2026-55042MEDIUMCVSS 5.5EG 5.52026-07-14
Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.
- CVE-2026-50690MEDIUMCVSS 5.5EG 5.52026-07-14
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
- CVE-2026-50455MEDIUMCVSS 5.5EG 5.52026-07-14
Use of uninitialized resource in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
- CVE-2026-49801MEDIUMCVSS 5.5EG 5.52026-07-14
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
- CVE-2026-40422MEDIUMCVSS 5.5EG 5.52026-07-14
Use of uninitialized resource in Windows File Explorer allows an authorized attacker to disclose information locally.
- CVE-2026-54997MEDIUMCVSS 5.5EG 5.52026-07-14
Use of uninitialized resource in Windows SMB allows an authorized attacker to disclose information locally.
- CVE-2026-53344MEDIUMCVSS 5.5EG 5.52026-07-01
In the Linux kernel, the following vulnerability has been resolved: pinctrl: mcp23s08: Initialize mcp->dev and mcp->addr before regmap init Regmap initialization triggers regcache_maple_populate() which attempts SPI read to populate cach…
- CVE-2026-53347MEDIUMCVSS 5.5EG 5.52026-07-01
In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix driver removal with disabled KMS DRM atomic and modesetting aren't initialized if virtio-gpu driver built with disabled KMS, leading to access of uniniti…
- CVE-2026-53311MEDIUMCVSS 5.5EG 5.52026-06-26
In the Linux kernel, the following vulnerability has been resolved: fuse: fix uninit-value in fuse_dentry_revalidate() fuse_dentry_revalidate() may be called with a dentry that didn't had ->d_time initialised. The issue was found with K…
- CVE-2026-53243MEDIUMCVSS 5.5EG 5.52026-06-25
In the Linux kernel, the following vulnerability has been resolved: rseq: Fix using an uninitialized stack variable in rseq_exit_user_update() There is an bug in which an uninitialized stack variable is used in rseq_exit_user_update() as…
- CVE-2026-53218MEDIUMCVSS 5.5EG 5.52026-06-25
In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag nft_exthdr_init() passes user-controlled priv->len to nft_parse_register_store(), which marks that many b…
- CVE-2026-53167MEDIUMCVSS 5.5EG 5.52026-06-25
In the Linux kernel, the following vulnerability has been resolved: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios FUSE_NOTIFY_RETRIEVE must be limited to uptodate folios; !uptodate folios can contain uninitialized data. Since FUSE_…
- CVE-2026-53142MEDIUMCVSS 5.5EG 5.52026-06-25
In the Linux kernel, the following vulnerability has been resolved: drm/xe/display: fix oops in suspend/shutdown without display The xe driver keeps track of whether to probe display, and whether display hardware is there, using xe->info…
- CVE-2026-53082MEDIUMCVSS 5.5EG 5.52026-06-24
In the Linux kernel, the following vulnerability has been resolved: net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf sixpack_receive_buf() does not properly skip bytes with TTY error flags. The while loop iterates through th…
- CVE-2026-53029MEDIUMCVSS 5.5EG 5.52026-06-24
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: prevent uninitialized lcn caused by zero len syzbot reported a uninit-value in ntfs_iomap_begin [1]. Since runs was not touched yet, run_lookup_entry() immedi…
- CVE-2026-52985MEDIUMCVSS 5.5EG 5.52026-06-24
In the Linux kernel, the following vulnerability has been resolved: netdevsim: zero initialize struct iphdr in dummy sk_buff Syzbot reports a KMSAN uninit-value originating from nsim_dev_trap_skb_build, with the allocation also being per…
- CVE-2026-42969MEDIUMCVSS 5.5EG 5.52026-06-09
Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.
- CVE-2026-46257MEDIUMCVSS 5.5EG 5.52026-06-03
In the Linux kernel, the following vulnerability has been resolved: clocksource/drivers/timer-sp804: Fix an Oops when read_current_timer is called on ARM32 platforms where the SP804 is not registered as the sched_clock. On SP804, the del…
- CVE-2026-46169MEDIUMCVSS 5.5EG 5.52026-05-28
In the Linux kernel, the following vulnerability has been resolved: hfsplus: fix uninit-value by validating catalog record size Syzbot reported a KMSAN uninit-value issue in hfsplus_strcasecmp(). The root cause is that hfs_brec_read() do…
- CVE-2026-46139MEDIUMCVSS 5.5EG 5.52026-05-28
In the Linux kernel, the following vulnerability has been resolved: smb: client: use kzalloc to zero-initialize security descriptor buffer Commit 62e7dd0a39c2d ("smb: common: change the data type of num_aces to le16") split struct smb_ac…
- CVE-2026-46132MEDIUMCVSS 5.5EG 5.52026-05-28
In the Linux kernel, the following vulnerability has been resolved: net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_vfinfo rtnl_fill_vfinfo() declares struct ifla_vf_broadcast on the stack without initialisati…
- CVE-2025-71311MEDIUMCVSS 5.5EG 5.52026-05-27
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios before use KMSAN reports an uninitialized value in longest_match_std(), invoked from ntfs_compress_write(). When new folios are allocated…
- CVE-2026-45886MEDIUMCVSS 5.5EG 5.52026-05-27
In the Linux kernel, the following vulnerability has been resolved: bpf: Fix bpf_xdp_store_bytes proto for read-only arg While making some maps in Cilium read-only from the BPF side, we noticed that the bpf_xdp_store_bytes proto is incor…
- CVE-2026-43474MEDIUMCVSS 5.5EG 5.52026-05-08
In the Linux kernel, the following vulnerability has been resolved: fs: init flags_valid before calling vfs_fileattr_get syzbot reported a uninit-value bug in [1]. Similar to the "*get" context where the kernel's internal file_kattr str…
Map vulnerabilities like CWE-908 to your infrastructure
EchelonGraph correlates every CVE — across CWE-908 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →