CVE-2025-71311
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios before use KMSAN reports an uninitiali
CVSS
8.2
High
EPSS
0.3%
p25
KEV
—
Exploit Today
8
0-100
Published: May 27, 2026 · Last modified: Jul 30, 2026 · CWE-908
0.3%EPSS · 30 days0.3%
2026-08-172026-09-13
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Initialize new folios before use KMSAN reports an uninitialized value in longest_match_std(), invoked from ntfs_compress_write(). When new folios are allocated without being marked uptodate and ni_read_frame() is skipped because the caller expects the frame to be completely overwritten, some reserved folios may remain only partially filled, leaving the rest memory uninitialized.
- git.kernel.orghttps://git.kernel.org/stable/c/41d79f8e2a36622d148719bf7c18b46ac1264284
- git.kernel.orghttps://git.kernel.org/stable/c/5a30cc03bde169ad558695b26da6ea7e55f6194a
- git.kernel.orghttps://git.kernel.org/stable/c/dd6c81527d097b3b0bf5a15c2fdc9657d045144c
- git.kernel.orghttps://git.kernel.org/stable/c/f223ebffa185cc8da934333c5a31ff2d4f992dc9
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-15710—1.1%
——0An information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141. An internal communication channel used by the user-space hook DLL to pass messages through the kernel driver to the daemon lacked proper token-based message validation, allowing local unprivileged processes to send unauthorized queries. Additionally, a reply buffer used by the port message handler was not properly initialized before returning data, leaking residual kernel pool memory from prior allocations. A local unprivileged attacker could exploit this vulnerability to enumerate DLP configuration and feature flags, extract live session tokens, and read kernel memory fragments from other users' operations.4dCVE-2026-87647—8.2%
——2Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)6dCVE-2026-876424.3 MED16.6%
——5Uninitialized resource in WebGL in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)6dCVE-2026-87576—9.4%
——3Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)6dCVE-2026-87555—23.7%
——7Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)6dCVE-2026-874974.3 MED10.5%
——3Uninitialized resource in Codecs in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)5d