What is CVE-2026-49425?
CVE-2026-49425 is a kernel stack information leak caused by the `compat32 kevent()` handler failing to zero the stack-declared structure when translating a 64-bit struct to a 32-bit struct. This may allow an unprivileged user to observe sensitive uninitialized kernel data. Affected systems should apply kernel updates immediately.
Azərbaycanca: CVE-2026-49425, `compat32 kevent()` funksiyasında 64-bit strukturu 32-bit strukturuna çevirərkən stack-də yerləşən strukturu sıfırlamamaqdan qaynaqlanan kernel stack məlumat sızıntısıdır. Bu zəiflik imtiyazsız istifadəçiyə kernel yaddaşındakı həssas məlumatları müşahidə etməyə imkan verə bilər. Təsirə məruz qalan sistemlərdə kernel yeniləməsi tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What type of vulnerability is CVE-2026-49425?
It is a kernel stack information leak vulnerability.
Who can exploit this vulnerability?
An unprivileged user can exploit this vulnerability to observe sensitive kernel data.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.