Out-of-bounds read in Linux kernel - CVE-2026-89532
Published: September 12, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an integer underflow resulting in an out-of-bounds read in the pcl_for_each_segment macro when processing a Write or Reply chunk with zero segments. A remote attacker can send a crafted Write or Reply chunk advertising zero segments to cause a denial of service.
The transport must have negotiated Send-With-Invalidate.