To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the current time for the timer's clock. (CVE-2026-58084)
Description
CVE-2026-58084 is a kernel vulnerability where the function realtimer_gettime() fails to check for errors when retrieving the current time for a CLOCK_TAI timer. This leads to copying uninitialized kernel stack memory to userspace. An unprivileged local user can exploit this by creating a POSIX timer with CLOCK_TAI and calling timer_settime(2), potentially disclosing sensitive kernel data.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability arises because realtimer_gettime() does not verify the error return when no TAI offset has been configured for a CLOCK_TAI timer. Consequently, an uninitialized output buffer containing kernel stack memory is copied to userspace. This allows an unprivileged local user to read uninitialized kernel memory by creating a POSIX timer with CLOCK_TAI and invoking timer_settime(2).
Potential Impact
An unprivileged local user can obtain uninitialized kernel stack memory, potentially exposing sensitive kernel data. This information disclosure could aid further attacks or compromise system confidentiality.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-p4v3-cw55-5mrc
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-58084"]
Threat ID: 6a85b4a4acd9273b492507a7
Added to database: 08/19/2026, 13:50:28 UTC
Last enriched: 08/19/2026, 13:58:40 UTC
Last updated: 10/04/2026, 10:02:28 UTC
Views: 25
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.