CWE-908
AllowedUse of Uninitialized Resource
Abstraction: Base · Status: Incomplete
The product uses or accesses a resource that has not been initialized.
1002 vulnerabilities reference this CWE, most recent first.
GHSA-753Q-378M-WC5V
Vulnerability from github – Published: 2026-10-06 21:31 – Updated: 2026-10-07 18:32Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
{
"affected": [],
"aliases": [
"CVE-2026-106290"
],
"database_specific": {
"cwe_ids": [
"CWE-908"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-10-06T19:17:56Z",
"severity": "MODERATE"
},
"details": "Uninitialized resource in GPU in Google Chrome on on Android prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)",
"id": "GHSA-753q-378m-wc5v",
"modified": "2026-10-07T18:32:02Z",
"published": "2026-10-06T21:31:45Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-106290"
},
{
"type": "WEB",
"url": "https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html"
},
{
"type": "WEB",
"url": "https://issues.chromium.org/issues/507351786"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-7638-FMXX-MR26
Vulnerability from github – Published: 2026-07-01 15:35 – Updated: 2026-07-24 00:32In the Linux kernel, the following vulnerability has been resolved:
pinctrl: mcp23s08: Initialize mcp->dev and mcp->addr before regmap init
Regmap initialization triggers regcache_maple_populate() which attempts SPI read to populate cache. SPI read requires mcp->dev and mcp->addr to be set, without them, NULL pointer dereference occurs during probe.
Move initialization before mcp23s08_spi_regmap_init() call.
{
"affected": [],
"aliases": [
"CVE-2026-53344"
],
"database_specific": {
"cwe_ids": [
"CWE-908"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-07-01T14:16:42Z",
"severity": "MODERATE"
},
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\npinctrl: mcp23s08: Initialize mcp-\u003edev and mcp-\u003eaddr before regmap init\n\nRegmap initialization triggers regcache_maple_populate() which attempts\nSPI read to populate cache. SPI read requires mcp-\u003edev and mcp-\u003eaddr to\nbe set, without them, NULL pointer dereference occurs during probe.\n\nMove initialization before mcp23s08_spi_regmap_init() call.",
"id": "GHSA-7638-fmxx-mr26",
"modified": "2026-07-24T00:32:32Z",
"published": "2026-07-01T15:35:19Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-53344"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/3a13bb9540dfd7014c5601608afcbbadbbcfd673"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/8473c3a197b57ff01396f7a2ec6ddf65383820d4"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-764W-CH2J-96HF
Vulnerability from github – Published: 2022-05-13 01:03 – Updated: 2022-05-13 01:03The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
{
"affected": [],
"aliases": [
"CVE-2015-5165"
],
"database_specific": {
"cwe_ids": [
"CWE-908"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2015-08-12T14:59:00Z",
"severity": "HIGH"
},
"details": "The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.",
"id": "GHSA-764w-ch2j-96hf",
"modified": "2022-05-13T01:03:35Z",
"published": "2022-05-13T01:03:35Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2015-5165"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2015:1674"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2015:1683"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2015:1718"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2015:1739"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2015:1740"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2015:1793"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2015:1833"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2015-5165"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=1248760"
},
{
"type": "WEB",
"url": "https://www.arista.com/en/support/advisories-notices/security-advisories/1180-security-advisory-13"
},
{
"type": "WEB",
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2015-September/165373.html"
},
{
"type": "WEB",
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167792.html"
},
{
"type": "WEB",
"url": "http://lists.fedoraproject.org/pipermail/package-announce/2015-September/167820.html"
},
{
"type": "WEB",
"url": "http://lists.opensuse.org/opensuse-security-announce/2015-08/msg00018.html"
},
{
"type": "WEB",
"url": "http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00027.html"
},
{
"type": "WEB",
"url": "http://rhn.redhat.com/errata/RHSA-2015-1674.html"
},
{
"type": "WEB",
"url": "http://rhn.redhat.com/errata/RHSA-2015-1683.html"
},
{
"type": "WEB",
"url": "http://rhn.redhat.com/errata/RHSA-2015-1739.html"
},
{
"type": "WEB",
"url": "http://rhn.redhat.com/errata/RHSA-2015-1740.html"
},
{
"type": "WEB",
"url": "http://rhn.redhat.com/errata/RHSA-2015-1793.html"
},
{
"type": "WEB",
"url": "http://rhn.redhat.com/errata/RHSA-2015-1833.html"
},
{
"type": "WEB",
"url": "http://support.citrix.com/article/CTX201717"
},
{
"type": "WEB",
"url": "http://www.debian.org/security/2015/dsa-3348"
},
{
"type": "WEB",
"url": "http://www.debian.org/security/2015/dsa-3349"
},
{
"type": "WEB",
"url": "http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/76153"
},
{
"type": "WEB",
"url": "http://www.securitytracker.com/id/1033176"
},
{
"type": "WEB",
"url": "http://xenbits.xen.org/xsa/advisory-140.html"
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-7676-XQ8C-838G
Vulnerability from github – Published: 2024-11-28 06:32 – Updated: 2025-01-18 00:30In BnAudioPolicyService::onTransact of IAudioPolicyService.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
{
"affected": [],
"aliases": [
"CVE-2018-9377"
],
"database_specific": {
"cwe_ids": [
"CWE-908"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-28T01:15:04Z",
"severity": "MODERATE"
},
"details": "In BnAudioPolicyService::onTransact of IAudioPolicyService.cpp, there is a\u00a0possible information disclosure due to uninitialized data. This could lead\u00a0to local information disclosure with no additional execution privileges\u00a0needed. User interaction is not needed for exploitation.",
"id": "GHSA-7676-xq8c-838g",
"modified": "2025-01-18T00:30:47Z",
"published": "2024-11-28T06:32:41Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2018-9377"
},
{
"type": "WEB",
"url": "https://source.android.com/docs/security/bulletin/pixel/2018-06-01"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-776Q-X7MF-F2FF
Vulnerability from github – Published: 2024-11-09 12:30 – Updated: 2025-11-04 00:31In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: do not pass a stopped vif to the driver in .get_txpower
Avoid potentially crashing in the driver because of uninitialized private data
{
"affected": [],
"aliases": [
"CVE-2024-50237"
],
"database_specific": {
"cwe_ids": [
"CWE-908"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-11-09T11:15:09Z",
"severity": "MODERATE"
},
"details": "In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: do not pass a stopped vif to the driver in .get_txpower\n\nAvoid potentially crashing in the driver because of uninitialized private data",
"id": "GHSA-776q-x7mf-f2ff",
"modified": "2025-11-04T00:31:59Z",
"published": "2024-11-09T12:30:49Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-50237"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/393b6bc174b0dd21bb2a36c13b36e62fc3474a23"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/3ccf525a73d48e814634847f6d4a6150c6f0dffc"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/78b698fbf37208ee921ee4cedea75b5d33d6ea9f"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/8f6cd4d5bb7406656835a90e4f1a2192607f0c21"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/b0b862aa3dbcd16b3c4715259a825f48ca540088"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/b2bcbe5450b20641f512d6b26c6b256a5a4f847f"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/c21efba8b5a86537ccdf43f77536bad02f82776c"
},
{
"type": "WEB",
"url": "https://git.kernel.org/stable/c/ee35c423042c9e04079fdee3db545135d609d6ea"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2025/01/msg00001.html"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00002.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-7787-4VJC-4737
Vulnerability from github – Published: 2023-09-14 21:30 – Updated: 2023-11-04 06:34A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.
{
"affected": [],
"aliases": [
"CVE-2023-25585"
],
"database_specific": {
"cwe_ids": [
"CWE-908"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-09-14T21:15:10Z",
"severity": "MODERATE"
},
"details": "A flaw was found in Binutils. The use of an uninitialized field in the struct module *module may lead to application crash and local denial of service.",
"id": "GHSA-7787-4vjc-4737",
"modified": "2023-11-04T06:34:05Z",
"published": "2023-09-14T21:30:26Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-25585"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2023-25585"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2167498"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20231103-0003"
},
{
"type": "WEB",
"url": "https://sourceware.org/bugzilla/show_bug.cgi?id=29892"
},
{
"type": "WEB",
"url": "https://sourceware.org/git/gitweb.cgi?p=binutils-gdb.git;h=65cf035b8dc1df5d8020e0b1449514a3c42933e7"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-77PG-JQ65-MG2F
Vulnerability from github – Published: 2026-10-08 18:32 – Updated: 2026-10-08 18:32FFmpeg through 9.0.2 contains an uninitialized memory disclosure vulnerability in av_dynamic_hdr_plus_to_t35() that leaves up to three payload bytes uninitialized when tone_mapping_flag is 0. Attackers can supply crafted Matroska T.35 BlockAdditional or HEVC/AV1 SEI metadata so that remuxing or transcoding writes leaked process memory into output files.
{
"affected": [],
"aliases": [
"CVE-2026-107676"
],
"database_specific": {
"cwe_ids": [
"CWE-908"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-10-08T16:17:05Z",
"severity": "MODERATE"
},
"details": "FFmpeg through 9.0.2 contains an uninitialized memory disclosure vulnerability in av_dynamic_hdr_plus_to_t35() that leaves up to three payload bytes uninitialized when tone_mapping_flag is 0. Attackers can supply crafted Matroska T.35 BlockAdditional or HEVC/AV1 SEI metadata so that remuxing or transcoding writes leaked process memory into output files.",
"id": "GHSA-77pg-jq65-mg2f",
"modified": "2026-10-08T18:32:28Z",
"published": "2026-10-08T18:32:28Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-107676"
},
{
"type": "WEB",
"url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2c2f6e96e31795ae95a8f8323a493ffbc493111f"
},
{
"type": "WEB",
"url": "https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24590"
},
{
"type": "WEB",
"url": "https://ffmpeg.org"
},
{
"type": "WEB",
"url": "https://github.com/FFmpeg/FFmpeg/blob/n9.0.2/libavutil/hdr_dynamic_metadata.c#L374-L385"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/ffmpeg-through-9.0.2-uninitialized-memory-disclosure-via-hdr10-metadata-serializer"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-77V2-JF2H-WV8H
Vulnerability from github – Published: 2026-10-06 21:31 – Updated: 2026-10-07 18:32Uninitialized resource in Dawn in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)
{
"affected": [],
"aliases": [
"CVE-2026-106231"
],
"database_specific": {
"cwe_ids": [
"CWE-908"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-10-06T19:17:49Z",
"severity": "MODERATE"
},
"details": "Uninitialized resource in Dawn in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker to read memory outside the sandbox via a crafted HTML page. (Chromium security severity: High)",
"id": "GHSA-77v2-jf2h-wv8h",
"modified": "2026-10-07T18:32:01Z",
"published": "2026-10-06T21:31:43Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-106231"
},
{
"type": "WEB",
"url": "https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html"
},
{
"type": "WEB",
"url": "https://issues.chromium.org/issues/553115993"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-78G7-JM5H-PV8Q
Vulnerability from github – Published: 2025-08-12 18:31 – Updated: 2025-08-12 18:31Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
{
"affected": [],
"aliases": [
"CVE-2025-53138"
],
"database_specific": {
"cwe_ids": [
"CWE-908"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-08-12T18:15:37Z",
"severity": "MODERATE"
},
"details": "Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.",
"id": "GHSA-78g7-jm5h-pv8q",
"modified": "2025-08-12T18:31:31Z",
"published": "2025-08-12T18:31:31Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-53138"
},
{
"type": "WEB",
"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53138"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-78J4-R4GH-XCM9
Vulnerability from github – Published: 2022-07-12 00:00 – Updated: 2024-03-21 03:34softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex crash.
{
"affected": [],
"aliases": [
"CVE-2022-35414"
],
"database_specific": {
"cwe_ids": [
"CWE-908"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-07-11T02:15:00Z",
"severity": "HIGH"
},
"details": "softmmu/physmem.c in QEMU through 7.0.0 can perform an uninitialized read on the translate_fail path, leading to an io_readx or io_writex crash.",
"id": "GHSA-78j4-r4gh-xcm9",
"modified": "2024-03-21T03:34:15Z",
"published": "2022-07-12T00:00:59Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-35414"
},
{
"type": "WEB",
"url": "https://github.com/qemu/qemu/commit/3517fb726741c109cae7995f9ea46f0cab6187d6#diff-83c563ed6330dc5d49876f1116e7518b5c16654bbc6e9b4ea8e28f5833d576fcR482"
},
{
"type": "WEB",
"url": "https://github.com/qemu/qemu/commit/3517fb726741c109cae7995f9ea46f0cab6187d6#diff-83c563ed6330dc5d49876f1116e7518b5c16654bbc6e9b4ea8e28f5833d576fcR482.aa"
},
{
"type": "WEB",
"url": "https://github.com/qemu/qemu/commit/418ade7849ce7641c0f7333718caf5091a02fd4c"
},
{
"type": "WEB",
"url": "https://github.com/qemu/qemu/blob/f200ff158d5abcb974a6b597a962b6b2fbea2b06/softmmu/physmem.c"
},
{
"type": "WEB",
"url": "https://github.com/qemu/qemu/blob/v7.0.0/include/exec/cpu-all.h#L145-L148"
},
{
"type": "WEB",
"url": "https://gitlab.com/qemu-project/qemu/-/issues/1065"
},
{
"type": "WEB",
"url": "https://lists.debian.org/debian-lts-announce/2022/09/msg00008.html"
},
{
"type": "WEB",
"url": "https://sick.codes/sick-2022-113"
},
{
"type": "WEB",
"url": "https://www.mail-archive.com/qemu-devel%40nongnu.org/msg895266.html"
},
{
"type": "WEB",
"url": "https://www.mail-archive.com/qemu-devel@nongnu.org/msg895266.html"
},
{
"type": "WEB",
"url": "https://www.qemu.org/docs/master/system/security.html#non-virtualization-use-case"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
Mitigation
Explicitly initialize the resource before use. If this is performed through an API function or standard procedure, follow all required steps.
Mitigation
Pay close attention to complex conditionals that affect initialization, since some branches might not perform the initialization.
Mitigation
Avoid race conditions (CWE-362) during initialization routines.
Mitigation
Run or compile the product with settings that generate warnings about uninitialized variables or data.
No CAPEC attack patterns related to this CWE.