Description
In the Linux kernel, the following vulnerability has been resolved:

timers/itimer: Zero-init old itimerval before copy to userspace

On native sparc64, struct __kernel_old_timeval contains a four-byte hole
after tv_usec because tv_sec is 64-bit while __kernel_suseconds_t is 32-bit.
put_itimerval() fills only the named fields in a stack-allocated
__kernel_old_itimerval and copies the entire object to userspace, so
getitimer() can expose the two padding holes.

Zero-initialize the aggregate before assigning the fields so implicit
padding is deterministic before it crosses the user/kernel boundary.
Published: 2026-09-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Patch
AI Analysis

Impact

The issue occurs in Linux kernels on sparc64 hardware. The old itimerval structure has padding between a 64‑bit time field and a 32‑bit microsecond field. put_itimerval() fills only the named fields in a stack‑allocated __kernel_old_itimerval and copies the entire object to userspace, so getitimer() can expose the two padding holes. Zero‑initializing the aggregate before assigning the fields so implicit padding is deterministic before it crosses the user/kernel boundary mitigates the problem. This flaw is classified as CWE‑201 and only leads to information disclosure, not privilege escalation or denial of service.

Affected Systems

Linux kernels on sparc64 that do not incorporate the commit adding zero‑initialization to the __kernel_old_itimerval structure are affected. Kernel releases before that patch are vulnerable; other architectures are not impacted based on the description.

Risk and Exploitability

The CVSS score of 5.3 denotes moderate severity, while the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local user or application capable of calling getitimer, allowing unprivileged programs to read padding data but not gain higher privileges.

Generated by OpenCVE AI on September 15, 2026 at 20:10 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Linux kernel to a version that contains the zero‑initialization of __kernel_old_itimerval on sparc64, such as the latest stable release that includes the patch commit.
  • If a full kernel upgrade is not feasible, backport the specific commit that applies the zero‑initialization to your running kernel to ensure the padding is cleared before copy to userspace.
  • Implement capability or container restrictions so that only privileged processes can invoke getitimer, reducing the attack surface for potential information disclosure.

Generated by OpenCVE AI on September 15, 2026 at 20:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6528-1 linux security update
History

Mon, 14 Sep 2026 12:30:00 +0000


Sat, 12 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-201
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H'}

threat_severity

Moderate


Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description In the Linux kernel, the following vulnerability has been resolved: timers/itimer: Zero-init old itimerval before copy to userspace On native sparc64, struct __kernel_old_timeval contains a four-byte hole after tv_usec because tv_sec is 64-bit while __kernel_suseconds_t is 32-bit. put_itimerval() fills only the named fields in a stack-allocated __kernel_old_itimerval and copies the entire object to userspace, so getitimer() can expose the two padding holes. Zero-initialize the aggregate before assigning the fields so implicit padding is deterministic before it crosses the user/kernel boundary.
Title timers/itimer: Zero-init old itimerval before copy to userspace
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel
References

Subscriptions

Linux Linux Kernel
cve-icon MITRE

Status: PUBLISHED

Assigner: Linux

Published:

Updated: 2026-09-14T12:02:35.331Z

Reserved: 2026-09-11T19:38:34.764Z

Link: CVE-2026-89765

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-11T20:20:07.740

Modified: 2026-09-14T13:19:25.837

Link: CVE-2026-89765

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-11T19:47:05Z

Links: CVE-2026-89765 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T20:15:14Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data